CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,785)
page 41 of 90| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-46429 | Hig | 0.57 | 8.8 | 0.01 | Feb 10, 2025 | A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges. | ||
| CVE-2024-55557 | Cri | 0.57 | 9.8 | 0.01 | Dec 16, 2024 | ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials. | ||
| CVE-2024-53484 | Hig | 0.57 | 8.8 | 0.00 | Dec 2, 2024 | Ever Traduora 0.20.0 and below is vulnerable to Privilege Escalation due to the use of a hard-coded JWT signing key. | ||
| CVE-2024-5722 | Hig | 0.57 | 8.8 | 0.01 | Nov 22, 2024 | Logsign Unified SecOps Platform HTTP API Hard-coded Cryptographic Key Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required… | ||
| CVE-2024-49060 | Hig | 0.57 | 8.8 | 0.00 | Nov 15, 2024 | Azure Stack HCI Elevation of Privilege Vulnerability | ||
| CVE-2024-9486 | Cri | 0.57 | 9.8 | 0.02 | Oct 15, 2024 | A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the… | ||
| CVE-2024-28812 | Hig | 0.57 | 8.8 | 0.00 | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection. | ||
| CVE-2024-28809 | Hig | 0.57 | 8.8 | 0.00 | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials. | ||
| CVE-2024-8448 | Hig | 0.57 | 8.8 | 0.00 | Sep 30, 2024 | Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root shell. | ||
| CVE-2023-41612 | Hig | 0.57 | 8.8 | 0.00 | Sep 18, 2024 | Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card. | ||
| CVE-2023-41610 | Hig | 0.57 | 8.8 | 0.00 | Sep 18, 2024 | Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext. | ||
| CVE-2024-6890 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2024 | Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password. | ||
| CVE-2024-39838 | Hig | 0.57 | 8.8 | 0.00 | Aug 5, 2024 | ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the device. | ||
| CVE-2024-5471 | Hig | 0.57 | 8.8 | 0.02 | Jul 17, 2024 | Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys. | ||
| CVE-2024-37630 | Hig | 0.57 | 8.8 | 0.00 | Jun 13, 2024 | D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as root. | ||
| CVE-2024-36264 | Cri | 0.57 | 9.8 | 0.01 | Jun 12, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this… | ||
| CVE-2023-49223 | Hig | 0.57 | 8.8 | 0.00 | Jun 7, 2024 | Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An attacker could exploit this to extract files and obtain sensitive information. | ||
| CVE-2023-49222 | Hig | 0.57 | 8.8 | 0.00 | Jun 7, 2024 | Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root privileges. | ||
| CVE-2023-35724 | Hig | 0.57 | 8.8 | 0.01 | May 3, 2024 | D-Link DAP-2622 Telnet CLI Use of Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this… | ||
| CVE-2023-32145 | Hig | 0.57 | 8.8 | 0.01 | May 3, 2024 | D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The… |
- risk 0.57cvss 8.8epss 0.01
A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges.
- risk 0.57cvss 9.8epss 0.01
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.
- risk 0.57cvss 8.8epss 0.00
Ever Traduora 0.20.0 and below is vulnerable to Privilege Escalation due to the use of a hard-coded JWT signing key.
- risk 0.57cvss 8.8epss 0.01
Logsign Unified SecOps Platform HTTP API Hard-coded Cryptographic Key Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required…
- risk 0.57cvss 8.8epss 0.00
Azure Stack HCI Elevation of Privilege Vulnerability
- risk 0.57cvss 9.8epss 0.02
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the…
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.
- risk 0.57cvss 8.8epss 0.00
Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root shell.
- risk 0.57cvss 8.8epss 0.00
Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.
- risk 0.57cvss 8.8epss 0.00
Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.
- risk 0.57cvss 8.8epss 0.01
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.
- risk 0.57cvss 8.8epss 0.00
ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the device.
- risk 0.57cvss 8.8epss 0.02
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.
- risk 0.57cvss 8.8epss 0.00
D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as root.
- risk 0.57cvss 9.8epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this…
- risk 0.57cvss 8.8epss 0.00
Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An attacker could exploit this to extract files and obtain sensitive information.
- risk 0.57cvss 8.8epss 0.00
Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root privileges.
- risk 0.57cvss 8.8epss 0.01
D-Link DAP-2622 Telnet CLI Use of Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this…
- risk 0.57cvss 8.8epss 0.01
D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The…