VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 3 of 89
  • CVE-2008-1160CriMar 25, 2008
    risk 0.68cvss 9.8epss 0.15

    ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.

  • CVE-2025-8730CriAug 8, 2025
    risk 0.67cvss 9.8epss 0.03

    A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to hard-coded credentials. The attack may be launched remotely. The…

  • CVE-2023-45499CriOct 27, 2023
    risk 0.67cvss 9.8epss 0.08

    VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.

  • CVE-2020-26879CriOct 26, 2020
    risk 0.67cvss 9.8epss 0.45

    Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.

  • CVE-2012-5686CriFeb 4, 2020
    risk 0.67cvss 9.8epss 0.05

    ZPanel 10.0.1 has insufficient entropy for its password reset process.

  • CVE-2019-16399CriSep 18, 2019
    risk 0.67cvss 9.8epss 0.07

    Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root…

  • CVE-2019-8352CriMay 20, 2019
    risk 0.67cvss 9.8epss 0.06

    By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these credentials and use…

  • CVE-2019-3932CriApr 30, 2019
    risk 0.67cvss 9.8epss 0.36

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated attacker can use this vulnerability to control external devices via the uart_bridge.

  • CVE-2018-10575CriApr 30, 2018
    risk 0.67cvss 9.8epss 0.09

    An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false.

  • CVE-2018-5723CriJan 16, 2018
    risk 0.67cvss 9.8epss 0.10

    MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.

  • CVE-2017-8224CriApr 25, 2017
    risk 0.67cvss 9.8epss 0.09

    Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET.

  • CVE-2016-5678CriAug 31, 2016
    risk 0.67cvss 9.8epss 0.09

    NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.

  • CVE-2025-20188CriMay 7, 2025
    risk 0.66cvss 10.0epss 0.27

    A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to…

  • CVE-2024-3408CriJun 6, 2024
    risk 0.66cvss 9.8epss 0.78

    man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge a session cookie if…

  • CVE-2021-44207HigKEVDec 21, 2021
    risk 0.66cvss 8.1epss 0.18

    Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.

  • CVE-2021-27164CriFeb 10, 2021
    risk 0.66cvss 9.8epss 0.24

    An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / aisadmin credentials for an ISP.

  • CVE-2021-27163CriFeb 10, 2021
    risk 0.66cvss 9.8epss 0.24

    An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / tele1234 credentials for an ISP.

  • CVE-2021-27162CriFeb 10, 2021
    risk 0.66cvss 9.8epss 0.27

    An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP.

  • CVE-2021-27159CriFeb 10, 2021
    risk 0.66cvss 9.8epss 0.24

    An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP.

  • CVE-2021-27158CriFeb 10, 2021
    risk 0.66cvss 9.8epss 0.24

    An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP.