VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 35 of 93
  • CVE-2016-6535CriSep 19, 2016
    risk 0.64cvss 9.8epss 0.02

    AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishing a TELNET session.

  • CVE-2016-5333CriAug 31, 2016
    risk 0.64cvss 9.8epss 0.02

    VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.

  • CVE-2016-5081CriAug 24, 2016
    risk 0.64cvss 9.8epss 0.03

    ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET session.

  • CVE-2016-2310CriJun 9, 2016
    risk 0.64cvss 9.8epss 0.03

    General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify configuration settings via the web…

  • CVE-2008-0961CriApr 14, 2008
    risk 0.64cvss 9.8epss 0.05

    EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface.

  • CVE-2005-0496CriFeb 21, 2005
    risk 0.64cvss 9.8epss 0.03

    Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.

  • CVE-2018-11311CriMay 20, 2018
    risk 0.63cvss 9.1epss 0.11

    A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.

  • CVE-2026-66890CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

  • CVE-2026-47281CriJun 9, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-3621CriJul 15, 2025
    risk 0.62cvss 9.6epss 0.01

    Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilities: * Improper Neutralization of Special Elements used in a Command ('Command Injection') * Use of Hard-coded…

  • CVE-2024-27107CriMay 14, 2024
    risk 0.62cvss 9.6epss 0.00

    Weak account password in GE HealthCare EchoPAC products

  • CVE-2023-22463CriJan 4, 2023
    risk 0.62cvss 9.8epss 0.70

    KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This means that an attacker can forge any jwt token to take over the administrator account of any online…

  • CVE-2021-45520CriDec 26, 2021
    risk 0.62cvss 9.6epss 0.00

    Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.

  • CVE-2021-28813CriSep 10, 2021
    risk 0.62cvss 9.6epss 0.01

    A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage…

  • CVE-2021-32454CriMay 17, 2021
    risk 0.62cvss 9.6epss 0.00

    SITEL CAP/PRX firmware version 5.2.01 makes use of a hardcoded password. An attacker with access to the device could modify these credentials, leaving the administrators of the device without access.

  • CVE-2020-10884HigMar 25, 2020
    risk 0.62cvss 8.8epss 0.26

    This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service,…

  • CVE-2026-11746CriJun 22, 2026
    risk 0.61cvss —epss 0.00

    A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the…

  • CVE-2025-59091CriJan 26, 2026
    risk 0.61cvss —epss 0.01

    Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This information, among other things, is used…

  • CVE-2018-25126CriNov 24, 2025
    risk 0.61cvss —epss 0.04

    Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and an OS command injection flaw in its configuration services. The web/API interface accepts HTTP/XML requests authenticated with a…

  • CVE-2025-56749CriOct 15, 2025
    risk 0.61cvss 9.4epss 0.00

    Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.