CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,842)
page 14 of 93| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-35396 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2024 | TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root. | ||
| CVE-2024-32053 | Cri | 0.64 | 9.8 | 0.00 | May 15, 2024 | Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel business application. | ||
| CVE-2024-32740 | Cri | 0.64 | 9.8 | 0.01 | May 14, 2024 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or over the network. | ||
| CVE-2024-31810 | Cri | 0.64 | 9.8 | 0.01 | May 14, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2023-44411 | Cri | 0.64 | 9.8 | 0.02 | May 3, 2024 | D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The… | ||
| CVE-2024-2161 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2024 | Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 . | ||
| CVE-2024-24681 | Cri | 0.64 | 9.8 | 0.01 | Feb 23, 2024 | An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations. | ||
| CVE-2024-0390 | Cri | 0.64 | 9.8 | 0.00 | Feb 15, 2024 | INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the… | ||
| CVE-2024-23816 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2024 | A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0) (All versions… | ||
| CVE-2023-38995 | Cri | 0.64 | 9.8 | 0.01 | Feb 7, 2024 | An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command. | ||
| CVE-2024-22853 | Cri | 0.64 | 9.8 | 0.05 | Feb 6, 2024 | D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session. | ||
| CVE-2024-21764 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port. | ||
| CVE-2024-1039 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2024 | Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device. | ||
| CVE-2024-24324 | Cri | 0.64 | 9.8 | 0.01 | Jan 30, 2024 | TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow. | ||
| CVE-2023-51840 | Cri | 0.64 | 9.8 | 0.01 | Jan 29, 2024 | DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key. | ||
| CVE-2024-23619 | Cri | 0.64 | 9.8 | 0.02 | Jan 26, 2024 | A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerability to achieve information disclosure or remote code execution. | ||
| CVE-2023-49253 | Cri | 0.64 | 9.8 | 0.01 | Jan 12, 2024 | Root user password is hardcoded into the device and cannot be changed in the user interface. | ||
| CVE-2023-48392 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2023 | Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including… | ||
| CVE-2023-48388 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2023 | Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service. | ||
| CVE-2023-40300 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key. |
- risk 0.64cvss 9.8epss 0.01
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.
- risk 0.64cvss 9.8epss 0.00
Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel business application.
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or over the network.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.64cvss 9.8epss 0.02
D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The…
- risk 0.64cvss 9.8epss 0.01
Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.
- risk 0.64cvss 9.8epss 0.00
INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the…
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0) (All versions…
- risk 0.64cvss 9.8epss 0.01
An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command.
- risk 0.64cvss 9.8epss 0.05
D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.
- risk 0.64cvss 9.8epss 0.01
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port.
- risk 0.64cvss 9.8epss 0.01
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.
- risk 0.64cvss 9.8epss 0.01
DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.
- risk 0.64cvss 9.8epss 0.02
A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerability to achieve information disclosure or remote code execution.
- risk 0.64cvss 9.8epss 0.01
Root user password is hardcoded into the device and cannot be changed in the user interface.
- risk 0.64cvss 9.8epss 0.01
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including…
- risk 0.64cvss 9.8epss 0.01
Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.
- risk 0.64cvss 9.8epss 0.01
NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.