VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 38 of 93
  • CVE-2023-27573CriMar 11, 2026
    risk 0.59cvss 9.0epss 0.00

    netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN). In practice on the public Internet, almost all users changed the password but only…

  • CVE-2025-1242CriFeb 25, 2026
    risk 0.59cvss 9.1epss 0.01

    The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware reverse engineering. The exposure may result in an attacker gaining full administrative access to the Gardyn IoT Hub exposing connected…

  • CVE-2026-24346CriJan 27, 2026
    risk 0.59cvss 9.1epss 0.00

    Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application

  • CVE-2025-68926CriDec 30, 2025
    risk 0.59cvss 9.8epss 0.31

    RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, hardcoded on both client and server…

  • CVE-2025-54455CriJul 23, 2025
    risk 0.59cvss 9.1epss 0.01

    Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.

  • CVE-2025-54454CriJul 23, 2025
    risk 0.59cvss 9.1epss 0.01

    Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.

  • CVE-2025-28230CriApr 18, 2025
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.

  • CVE-2024-36556CriFeb 6, 2025
    risk 0.59cvss 9.1epss 0.00

    Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b have a Hardcoded password vulnerability.

  • CVE-2024-57811CriJan 13, 2025
    risk 0.59cvss 9.1epss 0.00

    In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH. The root password is hardcoded in the firmware. NOTE: This vulnerability appears in versions that are no longer supported by Eaton.

  • CVE-2024-46505CriJan 9, 2025
    risk 0.59cvss 9.1epss 0.00

    Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

  • CVE-2024-36248CriNov 26, 2024
    risk 0.59cvss 9.1epss 0.01

    API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

  • CVE-2024-35244CriNov 26, 2024
    risk 0.59cvss 9.1epss 0.01

    There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), these accounts can be used to re-configure the device. As for the details of affected product names, model…

  • CVE-2024-10025CriOct 17, 2024
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the…

  • CVE-2023-27584CriSep 19, 2024
    risk 0.59cvss 9.8epss 0.34

    Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded,…

  • CVE-2024-28751CriJul 9, 2024
    risk 0.59cvss 9.1epss 0.01

    An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.

  • CVE-2024-28194CriMar 13, 2024
    risk 0.59cvss 9.1epss 0.01

    your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.8.0 use a hardcoded JSON Web Token (JWT) secret to sign authentication tokens. Attackers can use this well-known value to forge valid authentication tokens for arbitrary users. This…

  • CVE-2023-46706CriFeb 1, 2024
    risk 0.59cvss 9.1epss 0.01

    Multiple MachineSense devices have credentials unable to be changed by the user or administrator.

  • CVE-2023-37287CriJul 10, 2023
    risk 0.59cvss 9.1epss 0.01

    SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execute submission and approval processes.

  • CVE-2022-45766CriFeb 10, 2023
    risk 0.59cvss 9.1epss 0.01

    Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependability of electronic key boxes.

  • CVE-2022-38337CriDec 6, 2022
    risk 0.59cvss 9.1epss 0.01

    When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of Service (DoS) for the user if services like fail2ban are used.