CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,773)
page 2 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-11094 | Cri | 0.70 | 9.8 | 0.34 | May 15, 2018 | An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the… | ||
| CVE-2023-5074 | Cri | 0.69 | 9.8 | 0.68 | Sep 20, 2023 | Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28 | ||
| CVE-2021-22707 | Cri | 0.69 | 9.8 | 0.65 | Jul 21, 2021 | A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that… | ||
| CVE-2014-9614 | Cri | 0.69 | 9.8 | 0.69 | Feb 19, 2020 | The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/. | ||
| CVE-2019-19492 | Cri | 0.69 | 9.8 | 0.29 | Dec 2, 2019 | FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml. | ||
| CVE-2019-7265 | Cri | 0.69 | 9.8 | 0.23 | Jul 2, 2019 | Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH). | ||
| CVE-2017-18371 | Cri | 0.69 | 9.8 | 0.23 | May 2, 2019 | The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234.… | ||
| CVE-2018-16158 | Cri | 0.69 | 9.8 | 0.35 | Aug 30, 2018 | Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the… | ||
| CVE-2014-125121 | Cri | 0.68 | — | 0.01 | Jul 31, 2025 | Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combination of hardcoded SSH credentials (or SSH private key) and insecure permissions on a startup script. The devices ship with a… | ||
| CVE-2014-125115 | Cri | 0.68 | — | 0.02 | Jul 25, 2025 | An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly sanitize user input in the loginhash_data parameter, allowing attackers to extract administrator credentials or active session tokens… | ||
| CVE-2021-43136 | Cri | 0.68 | 9.8 | 0.16 | Nov 10, 2021 | An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform. | ||
| CVE-2020-24215 | Cri | 0.68 | 9.8 | 0.20 | Oct 6, 2020 | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin… | ||
| CVE-2020-11857 | Cri | 0.68 | 9.8 | 0.16 | Sep 22, 2020 | An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user | ||
| CVE-2013-6236 | Cri | 0.68 | 9.8 | 0.10 | Feb 12, 2020 | IZON IP 2.0.2: hard-coded password vulnerability | ||
| CVE-2018-11509 | Cri | 0.68 | 9.8 | 0.13 | Aug 16, 2018 | ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell. | ||
| CVE-2018-9161 | Cri | 0.68 | 9.8 | 0.57 | Mar 31, 2018 | Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account by reading user/scripts/login_par.js. | ||
| CVE-2015-4667 | Cri | 0.68 | 9.8 | 0.11 | Sep 25, 2017 | Multiple hardcoded credentials in Xsuite 2.x. | ||
| CVE-2015-7246 | Cri | 0.68 | 9.8 | 0.14 | Apr 24, 2017 | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative access. | ||
| CVE-2017-7462 | Cri | 0.68 | 9.8 | 0.13 | Apr 11, 2017 | Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory. | ||
| CVE-2017-6558 | Cri | 0.68 | 9.8 | 0.15 | Mar 9, 2017 | iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file. |
- risk 0.70cvss 9.8epss 0.34
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the…
- risk 0.69cvss 9.8epss 0.68
Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28
- risk 0.69cvss 9.8epss 0.65
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that…
- risk 0.69cvss 9.8epss 0.69
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.
- risk 0.69cvss 9.8epss 0.29
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
- risk 0.69cvss 9.8epss 0.23
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
- risk 0.69cvss 9.8epss 0.23
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234.…
- risk 0.69cvss 9.8epss 0.35
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the…
- risk 0.68cvss —epss 0.01
Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combination of hardcoded SSH credentials (or SSH private key) and insecure permissions on a startup script. The devices ship with a…
- risk 0.68cvss —epss 0.02
An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly sanitize user input in the loginhash_data parameter, allowing attackers to extract administrator credentials or active session tokens…
- risk 0.68cvss 9.8epss 0.16
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
- risk 0.68cvss 9.8epss 0.20
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin…
- risk 0.68cvss 9.8epss 0.16
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user
- risk 0.68cvss 9.8epss 0.10
IZON IP 2.0.2: hard-coded password vulnerability
- risk 0.68cvss 9.8epss 0.13
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.
- risk 0.68cvss 9.8epss 0.57
Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account by reading user/scripts/login_par.js.
- risk 0.68cvss 9.8epss 0.11
Multiple hardcoded credentials in Xsuite 2.x.
- risk 0.68cvss 9.8epss 0.14
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative access.
- risk 0.68cvss 9.8epss 0.13
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.
- risk 0.68cvss 9.8epss 0.15
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.