CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,842)
page 42 of 93| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-45466 | Hig | 0.57 | 8.8 | 0.01 | Jul 25, 2025 | Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext. | ||
| CVE-2025-49551 | Hig | 0.57 | 8.8 | 0.00 | Jul 8, 2025 | ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to sensitive systems or data. Exploitation… | ||
| CVE-2025-34034 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2025 | A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or… | ||
| CVE-2025-2765 | Hig | 0.57 | 8.8 | 0.00 | Apr 23, 2025 | CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to exploit… | ||
| CVE-2024-52902 | Hig | 0.57 | 8.8 | 0.00 | Feb 19, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system. | ||
| CVE-2024-46433 | Hig | 0.57 | 8.8 | 0.01 | Feb 10, 2025 | A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative privileges. | ||
| CVE-2024-46429 | Hig | 0.57 | 8.8 | 0.01 | Feb 10, 2025 | A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges. | ||
| CVE-2024-55557 | Cri | 0.57 | 9.8 | 0.01 | Dec 16, 2024 | ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials. | ||
| CVE-2024-53484 | Hig | 0.57 | 8.8 | 0.00 | Dec 2, 2024 | Ever Traduora 0.20.0 and below is vulnerable to Privilege Escalation due to the use of a hard-coded JWT signing key. | ||
| CVE-2024-5722 | Hig | 0.57 | 8.8 | 0.01 | Nov 22, 2024 | Logsign Unified SecOps Platform HTTP API Hard-coded Cryptographic Key Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required… | ||
| CVE-2024-49060 | Hig | 0.57 | 8.8 | 0.00 | Nov 15, 2024 | Azure Stack HCI Elevation of Privilege Vulnerability | ||
| CVE-2024-9486 | Cri | 0.57 | 9.8 | 0.02 | Oct 15, 2024 | A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the… | ||
| CVE-2024-28812 | Hig | 0.57 | 8.8 | 0.00 | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection. | ||
| CVE-2024-28809 | Hig | 0.57 | 8.8 | 0.00 | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials. | ||
| CVE-2024-8448 | Hig | 0.57 | 8.8 | 0.00 | Sep 30, 2024 | Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root shell. | ||
| CVE-2023-41612 | Hig | 0.57 | 8.8 | 0.00 | Sep 18, 2024 | Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card. | ||
| CVE-2023-41610 | Hig | 0.57 | 8.8 | 0.00 | Sep 18, 2024 | Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext. | ||
| CVE-2024-6890 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2024 | Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password. | ||
| CVE-2024-39838 | Hig | 0.57 | 8.8 | 0.00 | Aug 5, 2024 | ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the device. | ||
| CVE-2024-5471 | Hig | 0.57 | 8.8 | 0.02 | Jul 17, 2024 | Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys. |
- risk 0.57cvss 8.8epss 0.01
Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.
- risk 0.57cvss 8.8epss 0.00
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to sensitive systems or data. Exploitation…
- risk 0.57cvss 8.8epss 0.01
A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or…
- risk 0.57cvss 8.8epss 0.00
CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to exploit…
- risk 0.57cvss 8.8epss 0.00
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.
- risk 0.57cvss 8.8epss 0.01
A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative privileges.
- risk 0.57cvss 8.8epss 0.01
A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges.
- risk 0.57cvss 9.8epss 0.01
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.
- risk 0.57cvss 8.8epss 0.00
Ever Traduora 0.20.0 and below is vulnerable to Privilege Escalation due to the use of a hard-coded JWT signing key.
- risk 0.57cvss 8.8epss 0.01
Logsign Unified SecOps Platform HTTP API Hard-coded Cryptographic Key Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required…
- risk 0.57cvss 8.8epss 0.00
Azure Stack HCI Elevation of Privilege Vulnerability
- risk 0.57cvss 9.8epss 0.02
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the…
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.
- risk 0.57cvss 8.8epss 0.00
Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root shell.
- risk 0.57cvss 8.8epss 0.00
Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.
- risk 0.57cvss 8.8epss 0.00
Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.
- risk 0.57cvss 8.8epss 0.01
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.
- risk 0.57cvss 8.8epss 0.00
ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the device.
- risk 0.57cvss 8.8epss 0.02
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.