VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 11 of 93
  • CVE-2025-30125CriJul 28, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an insecure-by-default condition. For users who change their passwords, it's limited to 8 characters. These short passwords…

  • CVE-2025-52376CriJul 15, 2025
    risk 0.64cvss 9.8epss 0.11

    An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotely enable the Telnet service without authentication, bypassing security controls. The Telnet server…

  • CVE-2025-7401CriJul 11, 2025
    risk 0.64cvss 9.8epss 0.01

    The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This…

  • CVE-2025-37103CriJul 8, 2025
    risk 0.64cvss 9.8epss 0.01

    Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.

  • CVE-2025-45813CriJul 2, 2025
    risk 0.64cvss 9.8epss 0.00

    ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.

  • CVE-2025-45784CriJun 18, 2025
    risk 0.64cvss 9.8epss 0.01

    D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user credentials. An attacker with access to the firmware image can extract these credentials using static analysis tools such as strings or…

  • CVE-2025-46352CriMay 30, 2025
    risk 0.64cvss 9.8epss 0.01

    The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string in the binary responsible for running VNC. This password cannot be altered, allowing anyone with knowledge of it to gain remote access to the panel. Such …

  • CVE-2025-32985CriApr 25, 2025
    risk 0.64cvss 9.8epss 0.00

    NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.

  • CVE-2025-46274CriApr 24, 2025
    risk 0.64cvss 9.8epss 0.01

    UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed database.

  • CVE-2025-46273CriApr 24, 2025
    risk 0.64cvss 9.8epss 0.01

    UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devices.

  • CVE-2025-2538CriMar 20, 2025
    risk 0.64cvss 9.8epss 0.01

    A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated attacker to gain administrative access to the system.

  • CVE-2025-30137CriMar 18, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for ports 9091 and 9092. The GNET mobile application contains hardcoded credentials that provide unauthorized access to the dashcam's API endpoints on ports 9091 and 9092. Once the GNET…

  • CVE-2025-30123CriMar 18, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the FTPX user account, enabling attackers to gain unauthorized access and extract sensitive recorded footage from the device.

  • CVE-2025-30122CriMar 18, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for attackers to gain unauthorized access to multiple devices.

  • CVE-2025-30113CriMar 18, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashcam's Android application contains hardcoded credentials that allow unauthorized access to device settings through ports 9091 and…

  • CVE-2025-1393CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can use hard-coded credentials to gain full administration privileges on the affected product.

  • CVE-2025-27643CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Hardcoded AWS API Key V-2024-006.

  • CVE-2025-25570CriFeb 27, 2025
    risk 0.64cvss 9.8epss 0.02

    Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.

  • CVE-2024-57040CriFeb 26, 2025
    risk 0.64cvss 9.8epss 0.01

    TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained by analyzing downloaded firmware or via a brute force attack through physical access to the…

  • CVE-2024-50688CriFeb 26, 2025
    risk 0.64cvss 9.8epss 0.01

    SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry.