CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,773)
page 3 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2008-1160 | Cri | 0.68 | 9.8 | 0.15 | Mar 25, 2008 | ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges. | ||
| CVE-2025-8730 | Cri | 0.67 | 9.8 | 0.03 | Aug 8, 2025 | A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to hard-coded credentials. The attack may be launched remotely. The… | ||
| CVE-2023-45499 | Cri | 0.67 | 9.8 | 0.08 | Oct 27, 2023 | VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials. | ||
| CVE-2020-26879 | Cri | 0.67 | 9.8 | 0.45 | Oct 26, 2020 | Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header. | ||
| CVE-2012-5686 | Cri | 0.67 | 9.8 | 0.05 | Feb 4, 2020 | ZPanel 10.0.1 has insufficient entropy for its password reset process. | ||
| CVE-2019-16399 | Cri | 0.67 | 9.8 | 0.07 | Sep 18, 2019 | Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root… | ||
| CVE-2019-8352 | Cri | 0.67 | 9.8 | 0.06 | May 20, 2019 | By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these credentials and use… | ||
| CVE-2019-3932 | Cri | 0.67 | 9.8 | 0.36 | Apr 30, 2019 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated attacker can use this vulnerability to control external devices via the uart_bridge. | ||
| CVE-2018-10575 | Cri | 0.67 | 9.8 | 0.09 | Apr 30, 2018 | An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false. | ||
| CVE-2018-5723 | Cri | 0.67 | 9.8 | 0.10 | Jan 16, 2018 | MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account. | ||
| CVE-2017-8224 | Cri | 0.67 | 9.8 | 0.09 | Apr 25, 2017 | Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET. | ||
| CVE-2016-5678 | Cri | 0.67 | 9.8 | 0.09 | Aug 31, 2016 | NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors. | ||
| CVE-2025-20188 | Cri | 0.66 | 10.0 | 0.27 | May 7, 2025 | A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to… | ||
| CVE-2024-3408 | Cri | 0.66 | 9.8 | 0.78 | Jun 6, 2024 | man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge a session cookie if… | ||
| CVE-2021-44207 | Hig | 0.66 | 8.1 | 0.18 | KEV | Dec 21, 2021 | Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials. | |
| CVE-2021-27164 | Cri | 0.66 | 9.8 | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / aisadmin credentials for an ISP. | ||
| CVE-2021-27163 | Cri | 0.66 | 9.8 | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / tele1234 credentials for an ISP. | ||
| CVE-2021-27162 | Cri | 0.66 | 9.8 | 0.27 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP. | ||
| CVE-2021-27159 | Cri | 0.66 | 9.8 | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP. | ||
| CVE-2021-27158 | Cri | 0.66 | 9.8 | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP. |
- risk 0.68cvss 9.8epss 0.15
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.
- risk 0.67cvss 9.8epss 0.03
A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to hard-coded credentials. The attack may be launched remotely. The…
- risk 0.67cvss 9.8epss 0.08
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.
- risk 0.67cvss 9.8epss 0.45
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.
- risk 0.67cvss 9.8epss 0.05
ZPanel 10.0.1 has insufficient entropy for its password reset process.
- risk 0.67cvss 9.8epss 0.07
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root…
- risk 0.67cvss 9.8epss 0.06
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these credentials and use…
- risk 0.67cvss 9.8epss 0.36
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated attacker can use this vulnerability to control external devices via the uart_bridge.
- risk 0.67cvss 9.8epss 0.09
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false.
- risk 0.67cvss 9.8epss 0.10
MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.
- risk 0.67cvss 9.8epss 0.09
Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET.
- risk 0.67cvss 9.8epss 0.09
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.
- risk 0.66cvss 10.0epss 0.27
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to…
- risk 0.66cvss 9.8epss 0.78
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge a session cookie if…
- risk 0.66cvss 8.1epss 0.18
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
- risk 0.66cvss 9.8epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / aisadmin credentials for an ISP.
- risk 0.66cvss 9.8epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / tele1234 credentials for an ISP.
- risk 0.66cvss 9.8epss 0.27
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP.
- risk 0.66cvss 9.8epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP.
- risk 0.66cvss 9.8epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP.