VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 36 of 90
  • CVE-2022-1162CriApr 4, 2022
    risk 0.61cvss 9.1epss 0.76

    A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

  • CVE-2021-43052CriJan 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret used in the default…

  • CVE-2019-19108CriApr 20, 2020
    risk 0.61cvss 9.4epss 0.02

    An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP.

  • CVE-2019-6693MedKEVNov 21, 2019
    risk 0.61cvss 6.5epss 0.06

    Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users'…

  • CVE-2018-5399CriOct 8, 2018
    risk 0.61cvss 9.4epss 0.02

    The Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 22 while the DCU is running. The Dropbear server is configured with a hard-coded user name and password combination of root / amroot. The server is configured…

  • CVE-2026-59507CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control

  • CVE-2025-13293CriAug 10, 2026
    risk 0.60cvss epss 0.00

    A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and…

  • CVE-2026-50110CriJun 30, 2026
    risk 0.60cvss 9.2epss 0.00

    Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to plaintext. The exposed credentials span a broad range of…

  • CVE-2025-10560CriJun 18, 2026
    risk 0.60cvss epss 0.00

    Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. The exposed credentials included AWS access keys, S3 bucket names, and related cloud access information. The originally exposed…

  • CVE-2026-5189CriApr 15, 2026
    risk 0.60cvss epss 0.00

    CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process…

  • CVE-2025-7072CriJan 9, 2026
    risk 0.60cvss epss 0.01

    The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an unauthenticated remote attacker could use to execute commands with root privileges. This vulnerability has been fixed in firmware…

  • CVE-2025-13954CriDec 10, 2025
    risk 0.60cvss epss 0.00

    Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authorization checks and gain full access to the admin UI

  • CVE-2025-7768CriAug 6, 2025
    risk 0.60cvss epss 0.01

    Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This vulnerability enables attackers to escalate privileges and take full control of the device, potentially modifying system settings,…

  • CVE-2025-4041CriMay 6, 2025
    risk 0.60cvss epss 0.01

    In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh server and utilize the system's components to perform OS command executions.

  • CVE-2024-48971CriNov 14, 2024
    risk 0.60cvss 9.3epss 0.00

    The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to gain unauthorized access to the device, with clinician privileges.

  • CVE-2024-20412CriOct 23, 2024
    risk 0.60cvss 9.3epss 0.00

    A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the presence of static…

  • CVE-2023-6198CriJun 25, 2024
    risk 0.60cvss 9.3epss 0.00

    Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows unauthorized access to the device.

  • CVE-2024-29855CriJun 11, 2024
    risk 0.60cvss 9.0epss 0.22

    Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator

  • CVE-2021-42833CriFeb 7, 2022
    risk 0.60cvss 9.3epss 0.00

    A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.

  • CVE-2026-67568CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.