CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,773)
page 14 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-22853 | Cri | 0.64 | 9.8 | 0.05 | Feb 6, 2024 | D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session. | ||
| CVE-2024-21764 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port. | ||
| CVE-2024-1039 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2024 | Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device. | ||
| CVE-2024-24324 | Cri | 0.64 | 9.8 | 0.01 | Jan 30, 2024 | TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow. | ||
| CVE-2023-51840 | Cri | 0.64 | 9.8 | 0.01 | Jan 29, 2024 | DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key. | ||
| CVE-2024-23619 | Cri | 0.64 | 9.8 | 0.02 | Jan 26, 2024 | A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerability to achieve information disclosure or remote code execution. | ||
| CVE-2023-49253 | Cri | 0.64 | 9.8 | 0.01 | Jan 12, 2024 | Root user password is hardcoded into the device and cannot be changed in the user interface. | ||
| CVE-2023-48392 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2023 | Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including… | ||
| CVE-2023-48388 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2023 | Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service. | ||
| CVE-2023-40300 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key. | ||
| CVE-2023-39169 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | The affected devices use publicly available default credentials with administrative privileges. | ||
| CVE-2023-23324 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account. | ||
| CVE-2023-47213 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2023 | First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB,… | ||
| CVE-2023-47800 | Cri | 0.64 | 9.8 | 0.01 | Nov 10, 2023 | Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or… | ||
| CVE-2023-5777 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2023 | Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the crash report server. | ||
| CVE-2018-17558 | Cri | 0.64 | 9.8 | 0.03 | Oct 26, 2023 | Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and… | ||
| CVE-2023-30801 | Cri | 0.64 | 9.8 | 0.01 | Oct 10, 2023 | All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials… | ||
| CVE-2023-36380 | Cri | 0.64 | 9.8 | 0.00 | Oct 10, 2023 | A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)). The affected devices contain a hard-coded ID in the SSH… | ||
| CVE-2023-20101 | Cri | 0.64 | 9.8 | 0.02 | Oct 4, 2023 | A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static… | ||
| CVE-2023-42336 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2023 | An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component. |
- risk 0.64cvss 9.8epss 0.05
D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.
- risk 0.64cvss 9.8epss 0.01
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port.
- risk 0.64cvss 9.8epss 0.01
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.
- risk 0.64cvss 9.8epss 0.01
DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.
- risk 0.64cvss 9.8epss 0.02
A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerability to achieve information disclosure or remote code execution.
- risk 0.64cvss 9.8epss 0.01
Root user password is hardcoded into the device and cannot be changed in the user interface.
- risk 0.64cvss 9.8epss 0.01
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including…
- risk 0.64cvss 9.8epss 0.01
Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.
- risk 0.64cvss 9.8epss 0.01
NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.
- risk 0.64cvss 9.8epss 0.01
The affected devices use publicly available default credentials with administrative privileges.
- risk 0.64cvss 9.8epss 0.01
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account.
- risk 0.64cvss 9.8epss 0.01
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB,…
- risk 0.64cvss 9.8epss 0.01
Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or…
- risk 0.64cvss 9.8epss 0.01
Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the crash report server.
- risk 0.64cvss 9.8epss 0.03
Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and…
- risk 0.64cvss 9.8epss 0.01
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials…
- risk 0.64cvss 9.8epss 0.00
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)). The affected devices contain a hard-coded ID in the SSH…
- risk 0.64cvss 9.8epss 0.02
A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static…
- risk 0.64cvss 9.8epss 0.01
An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component.