VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 36 of 93
  • CVE-2025-56749CriOct 15, 2025
    risk 0.61cvss 9.4epss 0.00

    Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.

  • CVE-2025-9696CriSep 2, 2025
    risk 0.61cvss —epss 0.00

    The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly accessible protocol details. An attacker within Bluetooth range could exploit this vulnerability to gain full access to the device's servicing interface. This…

  • CVE-2025-3321CriJun 6, 2025
    risk 0.61cvss —epss 0.00

    A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the network, only by local users on the server.

  • CVE-2024-49806CriNov 29, 2024
    risk 0.61cvss 9.4epss 0.00

    IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2024-49805CriNov 29, 2024
    risk 0.61cvss 9.4epss 0.00

    IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2022-47558CriSep 19, 2023
    risk 0.61cvss 9.4epss 0.01

    Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow an attacker to modify critical files that could allow the creation of new users, delete or modify existing users, modify…

  • CVE-2023-23770CriAug 29, 2023
    risk 0.61cvss 9.4epss 0.01

    Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

  • CVE-2023-1748CriApr 4, 2023
    risk 0.61cvss 9.3epss 0.01

    The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely…

  • CVE-2021-43116HigJul 5, 2022
    risk 0.61cvss 8.8epss 0.07

    An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.

  • CVE-2022-30234CriJun 2, 2022
    risk 0.61cvss 9.4epss 0.01

    A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtained. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

  • CVE-2022-31462CriJun 2, 2022
    risk 0.61cvss 9.3epss 0.01

    Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth broadcast data.

  • CVE-2022-1162CriApr 4, 2022
    risk 0.61cvss 9.1epss 0.76

    A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

  • CVE-2021-43052CriJan 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret used in the default…

  • CVE-2019-19108CriApr 20, 2020
    risk 0.61cvss 9.4epss 0.02

    An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP.

  • CVE-2019-6693MedKEVNov 21, 2019
    risk 0.61cvss 6.5epss 0.06

    Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users'…

  • CVE-2018-5399CriOct 8, 2018
    risk 0.61cvss 9.4epss 0.02

    The Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 22 while the DCU is running. The Dropbear server is configured with a hard-coded user name and password combination of root / amroot. The server is configured…

  • CVE-2026-13086CriAug 28, 2026
    risk 0.60cvss —epss 0.00

    A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

  • CVE-2026-78251CriAug 27, 2026
    risk 0.60cvss —epss 0.00

    DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in…

  • CVE-2026-59507CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    : Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP…

  • CVE-2025-13293CriAug 10, 2026
    risk 0.60cvss —epss 0.01

    A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and…