VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 17 of 89
  • CVE-2022-44097CriNov 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

  • CVE-2022-44096CriNov 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

  • CVE-2022-40602CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator.

  • CVE-2022-29889CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a hard-coded root password can lead to arbitrary command execution. An attacker can authenticate with hard-coded credentials to trigger this…

  • CVE-2022-29477CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP header can lead to authentication bypass. An attacker can send an HTTP request to trigger…

  • CVE-2022-42980CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.

  • CVE-2022-28812CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.

  • CVE-2022-22522CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.

  • CVE-2022-3214CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to  1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer…

  • CVE-2022-38823CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.

  • CVE-2022-38394CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attacker to execute an arbitrary OS command.

  • CVE-2022-40111CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.

  • CVE-2022-36672CriSep 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.

  • CVE-2022-30318CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.01

    Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH. The potential impact is: Remote code execution, manipulate…

  • CVE-2022-38116CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote attacker can access, modify system data or disrupt service.

  • CVE-2022-36560CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh.

  • CVE-2022-36558CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.

  • CVE-2022-35540CriAug 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.

  • CVE-2022-35491CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.

  • CVE-2022-22144CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a known root password. An attacker does not have to do…