VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 37 of 93
  • CVE-2026-50110CriJun 30, 2026
    risk 0.60cvss 9.2epss 0.00

    Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to plaintext. The exposed credentials span a broad range of…

  • CVE-2025-10560CriJun 18, 2026
    risk 0.60cvss —epss 0.00

    Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. The exposed credentials included AWS access keys, S3 bucket names, and related cloud access information. The originally exposed…

  • CVE-2025-7072CriJan 9, 2026
    risk 0.60cvss —epss 0.01

    The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an unauthenticated remote attacker could use to execute commands with root privileges. This vulnerability has been fixed in firmware…

  • CVE-2025-13954CriDec 10, 2025
    risk 0.60cvss —epss 0.00

    Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authorization checks and gain full access to the admin UI

  • CVE-2025-7768CriAug 6, 2025
    risk 0.60cvss —epss 0.01

    Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This vulnerability enables attackers to escalate privileges and take full control of the device, potentially modifying system settings,…

  • CVE-2025-4041CriMay 6, 2025
    risk 0.60cvss —epss 0.01

    In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh server and utilize the system's components to perform OS command executions.

  • CVE-2024-48971CriNov 14, 2024
    risk 0.60cvss 9.3epss 0.00

    The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to gain unauthorized access to the device, with clinician privileges.

  • CVE-2024-20412CriOct 23, 2024
    risk 0.60cvss 9.3epss 0.00

    A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the presence of static…

  • CVE-2023-6198CriJun 25, 2024
    risk 0.60cvss 9.3epss 0.00

    Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows unauthorized access to the device.

  • CVE-2024-29855CriJun 11, 2024
    risk 0.60cvss 9.0epss 0.22

    Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator

  • CVE-2021-42833CriFeb 7, 2022
    risk 0.60cvss 9.3epss 0.00

    A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.

  • CVE-2026-75940CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

  • CVE-2026-18931CriSep 1, 2026
    risk 0.59cvss 9.1epss 0.00

    Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.

  • CVE-2026-75896CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.00

    Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords. This issue affects Liderahenk: before 3.5.5.

  • CVE-2026-59769CriAug 25, 2026
    risk 0.59cvss 9.1epss 0.01

    FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.

  • CVE-2026-71960CriAug 19, 2026
    risk 0.59cvss 9.1epss 0.01

    Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image.…

  • CVE-2026-67568CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

  • CVE-2026-71238CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository…

  • CVE-2026-12628CriJun 22, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The…

  • CVE-2026-50083CriJun 12, 2026
    risk 0.59cvss 9.1epss 0.01

    The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with…