VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 18 of 93
  • CVE-2022-38394CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attacker to execute an arbitrary OS command.

  • CVE-2022-40111CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.

  • CVE-2022-36672CriSep 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.

  • CVE-2022-30318CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.02

    Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH. The potential impact is: Remote code execution, manipulate…

  • CVE-2022-38116CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote attacker can access, modify system data or disrupt service.

  • CVE-2022-36560CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh.

  • CVE-2022-36558CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.

  • CVE-2022-35540CriAug 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.

  • CVE-2022-35491CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.

  • CVE-2022-22144CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a known root password. An attacker does not have to do…

  • CVE-2022-34993CriAug 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.

  • CVE-2022-32965CriAug 4, 2022
    risk 0.64cvss 9.8epss 0.01

    OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code, manipulate system data and disrupt service.

  • CVE-2022-35866CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.04

    This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MySQL server. The…

  • CVE-2022-30274CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB…

  • CVE-2022-30271CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.

  • CVE-2022-29953CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.

  • CVE-2022-34045CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.03

    Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh.

  • CVE-2022-2107CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.

  • CVE-2022-24657CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect via the SSH protocol (port 22).

  • CVE-2022-32985CriJul 17, 2022
    risk 0.64cvss 9.8epss 0.01

    libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.