CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,845)
page 17 of 93| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-36224 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Western Digital My Cloud devices before OS5 have a nobody account with a blank password. | ||
| CVE-2023-24155 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini. | ||
| CVE-2023-24149 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow. | ||
| CVE-2022-48113 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2023 | A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials. | ||
| CVE-2023-22495 | Cri | 0.64 | 9.8 | 0.01 | Jan 14, 2023 | Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypass the authentication in this application when deployed using the official Docker image. Because a hard coded secret is used to sign the authentication token… | ||
| CVE-2022-39185 | Cri | 0.64 | 9.8 | 0.01 | Jan 12, 2023 | EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user. | ||
| CVE-2022-47618 | Cri | 0.64 | 9.8 | 0.01 | Jan 3, 2023 | Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service. | ||
| CVE-2022-37832 | Cri | 0.64 | 9.8 | 0.01 | Dec 16, 2022 | Mutiny 7.2.0-10788 suffers from Hardcoded root password. | ||
| CVE-2022-41653 | Cri | 0.64 | 9.8 | 0.01 | Dec 13, 2022 | Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control the system. | ||
| CVE-2022-2660 | Cri | 0.64 | 9.8 | 0.01 | Dec 13, 2022 | Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine. | ||
| CVE-2022-44097 | Cri | 0.64 | 9.8 | 0.01 | Nov 30, 2022 | Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel. | ||
| CVE-2022-44096 | Cri | 0.64 | 9.8 | 0.01 | Nov 30, 2022 | Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel. | ||
| CVE-2022-40602 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator. | ||
| CVE-2022-29889 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2022 | A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a hard-coded root password can lead to arbitrary command execution. An attacker can authenticate with hard-coded credentials to trigger this… | ||
| CVE-2022-29477 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2022 | An authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP header can lead to authentication bypass. An attacker can send an HTTP request to trigger… | ||
| CVE-2022-42980 | Cri | 0.64 | 9.8 | 0.01 | Oct 17, 2022 | go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key. | ||
| CVE-2022-28812 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2022 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device. | ||
| CVE-2022-22522 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2022 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device. | ||
| CVE-2022-3214 | Cri | 0.64 | 9.8 | 0.02 | Sep 16, 2022 | Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to 1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer… | ||
| CVE-2022-38823 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2022 | In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample. |
- risk 0.64cvss 9.8epss 0.01
Western Digital My Cloud devices before OS5 have a nobody account with a blank password.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.
- risk 0.64cvss 9.8epss 0.01
A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.
- risk 0.64cvss 9.8epss 0.01
Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypass the authentication in this application when deployed using the official Docker image. Because a hard coded secret is used to sign the authentication token…
- risk 0.64cvss 9.8epss 0.01
EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user.
- risk 0.64cvss 9.8epss 0.01
Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service.
- risk 0.64cvss 9.8epss 0.01
Mutiny 7.2.0-10788 suffers from Hardcoded root password.
- risk 0.64cvss 9.8epss 0.01
Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control the system.
- risk 0.64cvss 9.8epss 0.01
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.
- risk 0.64cvss 9.8epss 0.01
Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.
- risk 0.64cvss 9.8epss 0.01
Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.
- risk 0.64cvss 9.8epss 0.01
A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator.
- risk 0.64cvss 9.8epss 0.01
A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a hard-coded root password can lead to arbitrary command execution. An attacker can authenticate with hard-coded credentials to trigger this…
- risk 0.64cvss 9.8epss 0.01
An authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP header can lead to authentication bypass. An attacker can send an HTTP request to trigger…
- risk 0.64cvss 9.8epss 0.01
go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.
- risk 0.64cvss 9.8epss 0.01
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.
- risk 0.64cvss 9.8epss 0.01
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.
- risk 0.64cvss 9.8epss 0.02
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to 1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer…
- risk 0.64cvss 9.8epss 0.01
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.