CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,842)
page 13 of 93| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-41616 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2024 | D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service. | ||
| CVE-2024-41611 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2024 | In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands. | ||
| CVE-2024-41610 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2024 | D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands. | ||
| CVE-2024-6912 | Cri | 0.64 | 9.8 | 0.01 | Jul 22, 2024 | Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0. | ||
| CVE-2024-35338 | Cri | 0.64 | 9.8 | 0.01 | Jul 16, 2024 | Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root. | ||
| CVE-2024-28747 | Cri | 0.64 | 9.8 | 0.01 | Jul 9, 2024 | An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges. | ||
| CVE-2023-46685 | Cri | 0.64 | 9.8 | 0.01 | Jul 8, 2024 | A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution. | ||
| CVE-2024-4708 | Cri | 0.64 | 9.8 | 0.01 | Jul 2, 2024 | mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device. | ||
| CVE-2023-41919 | Cri | 0.64 | 9.8 | 0.00 | Jul 2, 2024 | Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access. | ||
| CVE-2024-39208 | Cri | 0.64 | 9.8 | 0.01 | Jun 27, 2024 | luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials. | ||
| CVE-2024-39374 | Cri | 0.64 | 9.8 | 0.01 | Jun 27, 2024 | TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials. | ||
| CVE-2024-0949 | Cri | 0.64 | 9.8 | 0.01 | Jun 27, 2024 | Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68. | ||
| CVE-2024-36480 | Cri | 0.64 | 9.8 | 0.00 | Jun 19, 2024 | Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the… | ||
| CVE-2024-38466 | Cri | 0.64 | 9.8 | 0.00 | Jun 16, 2024 | Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password. | ||
| CVE-2024-38281 | Cri | 0.64 | 9.8 | 0.00 | Jun 13, 2024 | An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device. | ||
| CVE-2024-3700 | Cri | 0.64 | 9.8 | 0.00 | Jun 10, 2024 | Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simple Care software in all versions. The… | ||
| CVE-2024-3699 | Cri | 0.64 | 9.8 | 0.00 | Jun 10, 2024 | Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet software versions from 7.0.0.0 through 9.17.0.0. | ||
| CVE-2024-1228 | Cri | 0.64 | 9.8 | 0.00 | Jun 10, 2024 | Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia software before version 20240417.001 (from… | ||
| CVE-2024-36782 | Cri | 0.64 | 9.8 | 0.00 | Jun 3, 2024 | TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root. | ||
| CVE-2024-5514 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2024 | MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend… |
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
- risk 0.64cvss 9.8epss 0.01
In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.
- risk 0.64cvss 9.8epss 0.01
Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.
- risk 0.64cvss 9.8epss 0.01
Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.
- risk 0.64cvss 9.8epss 0.01
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.
- risk 0.64cvss 9.8epss 0.01
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
- risk 0.64cvss 9.8epss 0.00
Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.
- risk 0.64cvss 9.8epss 0.01
luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.
- risk 0.64cvss 9.8epss 0.01
TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.
- risk 0.64cvss 9.8epss 0.01
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.
- risk 0.64cvss 9.8epss 0.00
Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the…
- risk 0.64cvss 9.8epss 0.00
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
- risk 0.64cvss 9.8epss 0.00
An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.
- risk 0.64cvss 9.8epss 0.00
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simple Care software in all versions. The…
- risk 0.64cvss 9.8epss 0.00
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet software versions from 7.0.0.0 through 9.17.0.0.
- risk 0.64cvss 9.8epss 0.00
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia software before version 20240417.001 (from…
- risk 0.64cvss 9.8epss 0.00
TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
- risk 0.64cvss 9.8epss 0.01
MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend…