VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 47 of 90
  • CVE-2021-27430HigMar 23, 2022
    risk 0.55cvss 8.4epss 0.00

    GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.

  • CVE-2019-15977HigJan 6, 2020
    risk 0.55cvss 7.5epss 0.38

    Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information…

  • CVE-2019-15017HigOct 9, 2019
    risk 0.55cvss 8.4epss 0.00

    The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker to authenticate to the service using hardcoded credentials.

  • CVE-2019-15015HigOct 9, 2019
    risk 0.55cvss 8.4epss 0.00

    In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthorized users gaining access to the system.

  • CVE-2019-1919HigJul 17, 2019
    risk 0.55cvss 8.4epss 0.00

    A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account that has root privileges. The vulnerability is due to the…

  • CVE-2018-17492HigMar 21, 2019
    risk 0.55cvss 8.4epss 0.00

    EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

  • CVE-2018-0141HigMar 8, 2018
    risk 0.55cvss 8.4epss 0.00

    A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded account password on the system. An attacker could exploit…

  • CVE-2026-42929HigMay 29, 2026
    risk 0.54cvss 8.3epss 0.00

    Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.

  • CVE-2025-55262HigMar 26, 2026
    risk 0.54cvss 8.3epss 0.00

    HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the database.

  • CVE-2026-4404CriMar 23, 2026
    risk 0.54cvss 9.4epss 0.00

    Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

  • CVE-2024-46436HigFeb 10, 2025
    risk 0.54cvss 8.3epss 0.00

    Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service.

  • CVE-2022-40259HigDec 5, 2022
    risk 0.54cvss 8.3epss 0.01

    MegaRAC Default Credentials Vulnerability

  • CVE-2022-31269HigAug 25, 2022
    risk 0.54cvss 8.2epss 0.05

    Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)

  • CVE-2026-19901HigAug 15, 2026
    risk 0.53cvss 8.1epss 0.00

    A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex.…

  • CVE-2026-19900HigAug 15, 2026
    risk 0.53cvss 8.1epss 0.00

    A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the…

  • CVE-2026-19871CriAug 14, 2026
    risk 0.53cvss epss 0.00

    Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save…

  • CVE-2026-18164HigAug 13, 2026
    risk 0.53cvss 8.1epss 0.00

    An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state.

  • CVE-2026-8982HigJul 21, 2026
    risk 0.53cvss 8.1epss 0.00

    Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to…

  • CVE-2026-61740CriJul 15, 2026
    risk 0.53cvss epss 0.00

    LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed because lightrag/api/auth.py falls back to a hardcoded DEFAULT_TOKEN_SECRET,…

  • CVE-2026-31928HigJun 26, 2026
    risk 0.53cvss 8.1epss 0.00

    The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.