VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 40 of 90
  • CVE-2026-42372HigMay 4, 2026
    risk 0.57cvss 8.8epss 0.00

    D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir605l" read from /etc/alpha_config/image_sign.…

  • CVE-2026-27785HigApr 28, 2026
    risk 0.57cvss 8.8epss 0.00

    Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.

  • CVE-2026-1958HigMar 23, 2026
    risk 0.57cvss epss 0.00

    Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several internal services. Critically, this included access to the FTP server that hosted the application's update packages. The attacker with these credentials could…

  • CVE-2026-4475HigMar 20, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The affected element is an unknown function of the file home/web/ipc. Such manipulation leads to hard-coded credentials. Access to the local network is required for this attack to succeed. The…

  • CVE-2026-2616HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has…

  • CVE-2025-59092HigJan 26, 2026
    risk 0.57cvss epss 0.01

    An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. This service is used for interprocess communication between services and the Kaba exos 9300 GUI, containing status information about the Access Managers.…

  • CVE-2025-54947CriDec 12, 2025
    risk 0.57cvss 9.8epss 0.00

    In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key.…

  • CVE-2025-14126HigDec 6, 2025
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the component Web Interface. Such manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been…

  • CVE-2025-33186HigNov 11, 2025
    risk 0.57cvss 8.8epss 0.00

    NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.

  • CVE-2025-62777HigOct 28, 2025
    risk 0.57cvss 8.8epss 0.00

    Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to log in to the affected device via Telnet and execute arbitrary commands.

  • CVE-2025-10639HigOct 21, 2025
    risk 0.57cvss 8.8epss 0.01

    The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with network access to this port can use weak hardcoded credentials to login to the FTP server and modify or read data, log files…

  • CVE-2025-57434HigSep 22, 2025
    risk 0.57cvss 8.8epss 0.00

    Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when the username is creabox and the password begins with the string creacast, regardless of what follows.

  • CVE-2025-52159HigSep 19, 2025
    risk 0.57cvss 8.8epss 0.00

    Hardcoded credentials in default configuration of PPress 0.0.9.

  • CVE-2025-51606HigAug 21, 2025
    risk 0.57cvss 8.8epss 0.00

    hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or compiled binary to forge valid access tokens and impersonate any user, including privileged ones such as "admin". The vulnerability…

  • CVE-2025-45466HigJul 25, 2025
    risk 0.57cvss 8.8epss 0.01

    Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.

  • CVE-2025-49551HigJul 8, 2025
    risk 0.57cvss 8.8epss 0.00

    ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to sensitive systems or data. Exploitation…

  • CVE-2025-34034HigJun 24, 2025
    risk 0.57cvss 8.8epss 0.01

    A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or…

  • CVE-2025-2765HigApr 23, 2025
    risk 0.57cvss 8.8epss 0.00

    CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to exploit…

  • CVE-2024-52902HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.00

    IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.

  • CVE-2024-46433HigFeb 10, 2025
    risk 0.57cvss 8.8epss 0.01

    A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative privileges.