VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 35 of 90
  • CVE-2024-27107CriMay 14, 2024
    risk 0.62cvss 9.6epss 0.00

    Weak account password in GE HealthCare EchoPAC products

  • CVE-2023-22463CriJan 4, 2023
    risk 0.62cvss 9.8epss 0.70

    KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This means that an attacker can forge any jwt token to take over the administrator account of any online…

  • CVE-2021-45520CriDec 26, 2021
    risk 0.62cvss 9.6epss 0.00

    Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.

  • CVE-2021-28813CriSep 10, 2021
    risk 0.62cvss 9.6epss 0.01

    A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage…

  • CVE-2021-32454CriMay 17, 2021
    risk 0.62cvss 9.6epss 0.00

    SITEL CAP/PRX firmware version 5.2.01 makes use of a hardcoded password. An attacker with access to the device could modify these credentials, leaving the administrators of the device without access.

  • CVE-2020-10884HigMar 25, 2020
    risk 0.62cvss 8.8epss 0.26

    This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service,…

  • CVE-2026-11746CriJun 22, 2026
    risk 0.61cvss epss 0.00

    A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the…

  • CVE-2025-59091CriJan 26, 2026
    risk 0.61cvss epss 0.01

    Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This information, among other things, is used…

  • CVE-2018-25126CriNov 24, 2025
    risk 0.61cvss epss 0.04

    Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and an OS command injection flaw in its configuration services. The web/API interface accepts HTTP/XML requests authenticated with a…

  • CVE-2025-56749CriOct 15, 2025
    risk 0.61cvss 9.4epss 0.00

    Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.

  • CVE-2025-9696CriSep 2, 2025
    risk 0.61cvss epss 0.00

    The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly accessible protocol details. An attacker within Bluetooth range could exploit this vulnerability to gain full access to the device's servicing interface. This…

  • CVE-2025-3321CriJun 6, 2025
    risk 0.61cvss epss 0.00

    A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the network, only by local users on the server.

  • CVE-2024-49806CriNov 29, 2024
    risk 0.61cvss 9.4epss 0.00

    IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2024-49805CriNov 29, 2024
    risk 0.61cvss 9.4epss 0.00

    IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2022-47558CriSep 19, 2023
    risk 0.61cvss 9.4epss 0.01

    Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow an attacker to modify critical files that could allow the creation of new users, delete or modify existing users, modify…

  • CVE-2023-23770CriAug 29, 2023
    risk 0.61cvss 9.4epss 0.01

    Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

  • CVE-2023-1748CriApr 4, 2023
    risk 0.61cvss 9.3epss 0.01

    The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely…

  • CVE-2021-43116HigJul 5, 2022
    risk 0.61cvss 8.8epss 0.07

    An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.

  • CVE-2022-30234CriJun 2, 2022
    risk 0.61cvss 9.4epss 0.01

    A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtained. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

  • CVE-2022-31462CriJun 2, 2022
    risk 0.61cvss 9.3epss 0.01

    Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth broadcast data.