VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 2 of 89
  • CVE-2018-11094CriMay 15, 2018
    risk 0.70cvss 9.8epss 0.34

    An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the…

  • CVE-2023-5074CriSep 20, 2023
    risk 0.69cvss 9.8epss 0.68

    Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28

  • CVE-2021-22707CriJul 21, 2021
    risk 0.69cvss 9.8epss 0.65

    A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that…

  • CVE-2014-9614CriFeb 19, 2020
    risk 0.69cvss 9.8epss 0.69

    The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.

  • CVE-2019-19492CriDec 2, 2019
    risk 0.69cvss 9.8epss 0.29

    FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.

  • CVE-2019-7265CriJul 2, 2019
    risk 0.69cvss 9.8epss 0.23

    Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).

  • CVE-2017-18371CriMay 2, 2019
    risk 0.69cvss 9.8epss 0.23

    The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234.…

  • CVE-2018-16158CriAug 30, 2018
    risk 0.69cvss 9.8epss 0.35

    Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the…

  • CVE-2014-125121CriJul 31, 2025
    risk 0.68cvss epss 0.01

    Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combination of hardcoded SSH credentials (or SSH private key) and insecure permissions on a startup script. The devices ship with a…

  • CVE-2014-125115CriJul 25, 2025
    risk 0.68cvss epss 0.02

    An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly sanitize user input in the loginhash_data parameter, allowing attackers to extract administrator credentials or active session tokens…

  • CVE-2021-43136CriNov 10, 2021
    risk 0.68cvss 9.8epss 0.16

    An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.

  • CVE-2020-24215CriOct 6, 2020
    risk 0.68cvss 9.8epss 0.20

    An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin…

  • CVE-2020-11857CriSep 22, 2020
    risk 0.68cvss 9.8epss 0.16

    An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user

  • CVE-2013-6236CriFeb 12, 2020
    risk 0.68cvss 9.8epss 0.10

    IZON IP 2.0.2: hard-coded password vulnerability

  • CVE-2018-11509CriAug 16, 2018
    risk 0.68cvss 9.8epss 0.13

    ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.

  • CVE-2018-9161CriMar 31, 2018
    risk 0.68cvss 9.8epss 0.57

    Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account by reading user/scripts/login_par.js.

  • CVE-2015-4667CriSep 25, 2017
    risk 0.68cvss 9.8epss 0.11

    Multiple hardcoded credentials in Xsuite 2.x.

  • CVE-2015-7246CriApr 24, 2017
    risk 0.68cvss 9.8epss 0.14

    D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative access.

  • CVE-2017-7462CriApr 11, 2017
    risk 0.68cvss 9.8epss 0.13

    Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.

  • CVE-2017-6558CriMar 9, 2017
    risk 0.68cvss 9.8epss 0.15

    iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.