CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,773)
page 12 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45656 | Cri | 0.64 | 9.8 | 0.00 | Oct 29, 2024 | IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privileges to the FSP. | ||
| CVE-2024-48539 | Cri | 0.64 | 9.8 | 0.00 | Oct 24, 2024 | Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism. | ||
| CVE-2024-45275 | Cri | 0.64 | 9.8 | 0.01 | Oct 15, 2024 | The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. | ||
| CVE-2024-43423 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2024 | The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed. | ||
| CVE-2024-45698 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2024 | Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can then be executed on the device. | ||
| CVE-2024-6656 | Cri | 0.64 | 9.8 | 0.00 | Sep 13, 2024 | Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Within an Executable. This issue affects Cockpit Software: before v2.13. | ||
| CVE-2024-6633 | Cri | 0.64 | 9.8 | 0.01 | Aug 27, 2024 | The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software. The HSQLDB is only… | ||
| CVE-2024-8162 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2024 | A vulnerability classified as critical has been found in TOTOLINK T10 AC1200 4.1.8cu.5207. Affected is an unknown function of the file /squashfs-root/web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to hard-coded credentials. It is possible to… | ||
| CVE-2024-42638 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2024 | H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. | |
| CVE-2024-42637 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2024 | H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. | |
| CVE-2024-41616 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2024 | D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service. | ||
| CVE-2024-41611 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2024 | In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands. | ||
| CVE-2024-41610 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2024 | D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands. | ||
| CVE-2024-6912 | Cri | 0.64 | 9.8 | 0.01 | Jul 22, 2024 | Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0. | ||
| CVE-2024-35338 | Cri | 0.64 | 9.8 | 0.01 | Jul 16, 2024 | Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root. | ||
| CVE-2024-28747 | Cri | 0.64 | 9.8 | 0.01 | Jul 9, 2024 | An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges. | ||
| CVE-2023-46685 | Cri | 0.64 | 9.8 | 0.01 | Jul 8, 2024 | A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution. | ||
| CVE-2024-4708 | Cri | 0.64 | 9.8 | 0.01 | Jul 2, 2024 | mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device. | ||
| CVE-2023-41919 | Cri | 0.64 | 9.8 | 0.00 | Jul 2, 2024 | Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access. | ||
| CVE-2024-39208 | Cri | 0.64 | 9.8 | 0.01 | Jun 27, 2024 | luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials. |
- risk 0.64cvss 9.8epss 0.00
IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privileges to the FSP.
- risk 0.64cvss 9.8epss 0.00
Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.
- risk 0.64cvss 9.8epss 0.01
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
- risk 0.64cvss 9.8epss 0.01
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.
- risk 0.64cvss 9.8epss 0.01
Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can then be executed on the device.
- risk 0.64cvss 9.8epss 0.00
Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Within an Executable. This issue affects Cockpit Software: before v2.13.
- risk 0.64cvss 9.8epss 0.01
The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software. The HSQLDB is only…
- risk 0.64cvss 9.8epss 0.02
A vulnerability classified as critical has been found in TOTOLINK T10 AC1200 4.1.8cu.5207. Affected is an unknown function of the file /squashfs-root/web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to hard-coded credentials. It is possible to…
- risk 0.64cvss 9.8epss 0.01
H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- risk 0.64cvss 9.8epss 0.01
H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
- risk 0.64cvss 9.8epss 0.01
In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.
- risk 0.64cvss 9.8epss 0.01
Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.
- risk 0.64cvss 9.8epss 0.01
Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.
- risk 0.64cvss 9.8epss 0.01
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.
- risk 0.64cvss 9.8epss 0.01
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
- risk 0.64cvss 9.8epss 0.00
Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.
- risk 0.64cvss 9.8epss 0.01
luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.