CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,785)
page 48 of 90| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-44825 | Hig | 0.53 | 8.1 | 0.02 | Jun 1, 2026 | Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently… | ||
| CVE-2026-1610 | Hig | 0.53 | 8.1 | 0.01 | Jan 29, 2026 | A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipulation results in hard-coded credentials. The attack is possible to be carried out remotely. A high degree of… | ||
| CVE-2025-68948 | Hig | 0.53 | 8.1 | 0.00 | Dec 27, 2025 | SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption ineffective. Since the… | ||
| CVE-2025-40938 | Hig | 0.53 | 8.1 | 0.00 | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the device’s confidentiality, integrity,… | ||
| CVE-2025-36087 | Hig | 0.53 | 8.1 | 0.00 | Oct 13, 2025 | IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound… | ||
| CVE-2025-3831 | Hig | 0.53 | 8.1 | 0.00 | Aug 12, 2025 | Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties. | ||
| CVE-2025-35940 | Hig | 0.53 | 8.1 | 0.00 | Jun 10, 2025 | The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL endpoints. | ||
| CVE-2024-9334 | Hig | 0.53 | 8.2 | 0.00 | Feb 27, 2025 | Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allows Authentication Bypass. This issue affects Pallium Vehicle Tracking: before 17.10.2024. | ||
| CVE-2024-31151 | Hig | 0.53 | 8.1 | 0.01 | Oct 30, 2024 | A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The… | ||
| CVE-2024-28875 | Hig | 0.53 | 8.1 | 0.01 | Oct 30, 2024 | A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The… | ||
| CVE-2024-5460 | Hig | 0.53 | 8.1 | 0.01 | Jun 26, 2024 | A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to… | ||
| CVE-2024-29170 | Hig | 0.53 | 8.1 | 0.00 | Jun 4, 2024 | Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure of network traffic and denial of service. | ||
| CVE-2023-5456 | Hig | 0.53 | 8.1 | 0.01 | Mar 5, 2024 | A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service and all included data with the same privileges of the web application. This issue affects: AiLux… | ||
| CVE-2023-48251 | Hig | 0.53 | 8.1 | 0.01 | Jan 10, 2024 | The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account. | ||
| CVE-2023-48250 | Hig | 0.53 | 8.1 | 0.01 | Jan 10, 2024 | The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts. | ||
| CVE-2023-43870 | Hig | 0.53 | 8.1 | 0.00 | Dec 19, 2023 | When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or reverse engineer the source code to gain access to the root certificate password. Using the root certificate and password they… | ||
| CVE-2023-40464 | Hig | 0.53 | 8.1 | 0.00 | Dec 4, 2023 | Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server. | ||
| CVE-2023-40463 | Hig | 0.53 | 8.1 | 0.01 | Dec 4, 2023 | When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access. … | ||
| CVE-2022-47891 | Hig | 0.53 | 8.1 | 0.01 | Oct 3, 2023 | All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function. | ||
| CVE-2023-0391 | Hig | 0.53 | 8.1 | 0.01 | Mar 21, 2023 | MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There has been no indication from the vendor this has been… |
- risk 0.53cvss 8.1epss 0.02
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently…
- risk 0.53cvss 8.1epss 0.01
A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipulation results in hard-coded credentials. The attack is possible to be carried out remotely. A high degree of…
- risk 0.53cvss 8.1epss 0.00
SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption ineffective. Since the…
- risk 0.53cvss 8.1epss 0.00
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the device’s confidentiality, integrity,…
- risk 0.53cvss 8.1epss 0.00
IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound…
- risk 0.53cvss 8.1epss 0.00
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
- risk 0.53cvss 8.1epss 0.00
The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL endpoints.
- risk 0.53cvss 8.2epss 0.00
Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allows Authentication Bypass. This issue affects Pallium Vehicle Tracking: before 17.10.2024.
- risk 0.53cvss 8.1epss 0.01
A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The…
- risk 0.53cvss 8.1epss 0.01
A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The…
- risk 0.53cvss 8.1epss 0.01
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to…
- risk 0.53cvss 8.1epss 0.00
Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure of network traffic and denial of service.
- risk 0.53cvss 8.1epss 0.01
A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service and all included data with the same privileges of the web application. This issue affects: AiLux…
- risk 0.53cvss 8.1epss 0.01
The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.
- risk 0.53cvss 8.1epss 0.01
The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.
- risk 0.53cvss 8.1epss 0.00
When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or reverse engineer the source code to gain access to the root certificate password. Using the root certificate and password they…
- risk 0.53cvss 8.1epss 0.00
Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.
- risk 0.53cvss 8.1epss 0.01
When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access. …
- risk 0.53cvss 8.1epss 0.01
All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function.
- risk 0.53cvss 8.1epss 0.01
MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There has been no indication from the vendor this has been…