CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,842)
page 48 of 93| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-1944 | Hig | 0.55 | 8.4 | 0.00 | May 24, 2023 | This vulnerability enables ssh access to minikube container using a default password. | ||
| CVE-2023-2504 | Hig | 0.55 | 8.4 | 0.00 | May 22, 2023 | Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials. | ||
| CVE-2022-34462 | Hig | 0.55 | 8.4 | 0.00 | Jan 18, 2023 | Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges. | ||
| CVE-2022-34440 | Hig | 0.55 | 8.4 | 0.00 | Jan 11, 2023 | Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin… | ||
| CVE-2022-36222 | Hig | 0.55 | 8.4 | 0.00 | Dec 21, 2022 | Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used locally to access the web admin interface. | ||
| CVE-2022-36952 | Hig | 0.55 | 8.4 | 0.01 | Jul 27, 2022 | In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10. | ||
| CVE-2021-27430 | Hig | 0.55 | 8.4 | 0.00 | Mar 23, 2022 | GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR. | ||
| CVE-2019-15977 | Hig | 0.55 | 7.5 | 0.38 | Jan 6, 2020 | Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information… | ||
| CVE-2019-15017 | Hig | 0.55 | 8.4 | 0.00 | Oct 9, 2019 | The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker to authenticate to the service using hardcoded credentials. | ||
| CVE-2019-15015 | Hig | 0.55 | 8.4 | 0.00 | Oct 9, 2019 | In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthorized users gaining access to the system. | ||
| CVE-2019-1919 | Hig | 0.55 | 8.4 | 0.00 | Jul 17, 2019 | A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account that has root privileges. The vulnerability is due to the… | ||
| CVE-2018-17492 | Hig | 0.55 | 8.4 | 0.00 | Mar 21, 2019 | EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application. | ||
| CVE-2018-0141 | Hig | 0.55 | 8.4 | 0.00 | Mar 8, 2018 | A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded account password on the system. An attacker could exploit… | ||
| CVE-2026-61740 | Cri | 0.54 | — | 0.01 | Jul 15, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed because lightrag/api/auth.py falls back to a hardcoded DEFAULT_TOKEN_SECRET,… | ||
| CVE-2026-42929 | Hig | 0.54 | 8.3 | 0.00 | May 29, 2026 | Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials. | ||
| CVE-2025-55262 | Hig | 0.54 | 8.3 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the database. | ||
| CVE-2026-4404 | Cri | 0.54 | 9.4 | 0.00 | Mar 23, 2026 | Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI. | ||
| CVE-2024-46436 | Hig | 0.54 | 8.3 | 0.00 | Feb 10, 2025 | Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service. | ||
| CVE-2022-40259 | Hig | 0.54 | 8.3 | 0.01 | Dec 5, 2022 | MegaRAC Default Credentials Vulnerability | ||
| CVE-2022-31269 | Hig | 0.54 | 8.2 | 0.07 | Aug 25, 2022 | Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.) |
- risk 0.55cvss 8.4epss 0.00
This vulnerability enables ssh access to minikube container using a default password.
- risk 0.55cvss 8.4epss 0.00
Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.
- risk 0.55cvss 8.4epss 0.00
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges.
- risk 0.55cvss 8.4epss 0.00
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin…
- risk 0.55cvss 8.4epss 0.00
Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used locally to access the web admin interface.
- risk 0.55cvss 8.4epss 0.01
In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
- risk 0.55cvss 8.4epss 0.00
GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.
- risk 0.55cvss 7.5epss 0.38
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information…
- risk 0.55cvss 8.4epss 0.00
The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker to authenticate to the service using hardcoded credentials.
- risk 0.55cvss 8.4epss 0.00
In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthorized users gaining access to the system.
- risk 0.55cvss 8.4epss 0.00
A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account that has root privileges. The vulnerability is due to the…
- risk 0.55cvss 8.4epss 0.00
EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.
- risk 0.55cvss 8.4epss 0.00
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded account password on the system. An attacker could exploit…
- risk 0.54cvss —epss 0.01
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed because lightrag/api/auth.py falls back to a hardcoded DEFAULT_TOKEN_SECRET,…
- risk 0.54cvss 8.3epss 0.00
Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.
- risk 0.54cvss 8.3epss 0.00
HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the database.
- risk 0.54cvss 9.4epss 0.00
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
- risk 0.54cvss 8.3epss 0.00
Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service.
- risk 0.54cvss 8.3epss 0.01
MegaRAC Default Credentials Vulnerability
- risk 0.54cvss 8.2epss 0.07
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)