VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 5 of 89
  • CVE-2023-2306CriOct 5, 2023
    risk 0.65cvss 10.0epss 0.00

    Qognify NiceVision versions 3.1 and prior are vulnerable to exposing sensitive information using hard-coded credentials. With these credentials an attacker can retrieve information about the cameras, user information, and modify database records.

  • CVE-2023-24022CriJan 26, 2023
    risk 0.65cvss 10.0epss 0.02

    Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily discovered and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by…

  • CVE-2022-45444CriJan 18, 2023
    risk 0.65cvss 10.0epss 0.01

    Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select users in the application’s database. This could allow a remote attacker to login to the database with unrestricted access.

  • CVE-2022-35413CriSep 13, 2022
    risk 0.65cvss 9.8epss 0.14

    WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.

  • CVE-2022-34907CriJul 25, 2022
    risk 0.65cvss 9.8epss 0.16

    An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.

  • CVE-2021-40422CriApr 14, 2022
    risk 0.65cvss 10.0epss 0.06

    An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2021-40519CriNov 10, 2021
    risk 0.65cvss 10.0epss 0.01

    Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials.

  • CVE-2021-0248CriApr 22, 2021
    risk 0.65cvss 10.0epss 0.01

    This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an attacker to take over any instance of an NFX deployment. This issue is only exploitable through administrative interfaces. This…

  • CVE-2021-27172CriFeb 10, 2021
    risk 0.65cvss 9.8epss 0.20

    An issue was discovered on FiberHome HG6245D devices through RP2613. A hardcoded GEPON password for root is defined inside /etc/init.d/system-config.sh.

  • CVE-2021-27169CriFeb 10, 2021
    risk 0.65cvss 9.8epss 0.20

    An issue was discovered on FiberHome AN5506-04-FA devices with firmware RP2631. There is a gepon password for the gepon account.

  • CVE-2021-27168CriFeb 10, 2021
    risk 0.65cvss 9.8epss 0.20

    An issue was discovered on FiberHome HG6245D devices through RP2613. There is a 6GFJdY4aAuUKJjdtSn7d password for the rdsadmin account.

  • CVE-2021-27167CriFeb 10, 2021
    risk 0.65cvss 9.8epss 0.15

    An issue was discovered on FiberHome HG6245D devices through RP2613. There is a password of four hexadecimal characters for the admin account. These characters are generated in init_3bb_password in libci_adaptation_layer.so.

  • CVE-2021-27166CriFeb 10, 2021
    risk 0.65cvss 9.8epss 0.20

    An issue was discovered on FiberHome HG6245D devices through RP2613. The password for the enable command is gpon.

  • CVE-2021-27165CriFeb 10, 2021
    risk 0.65cvss 9.8epss 0.20

    An issue was discovered on FiberHome HG6245D devices through RP2613. The telnet daemon on port 23/tcp can be abused with the gpon/gpon credentials.

  • CVE-2021-27161CriFeb 10, 2021
    risk 0.65cvss 9.8epss 0.17

    An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 1234 credentials for an ISP.

  • CVE-2021-27160CriFeb 10, 2021
    risk 0.65cvss 9.8epss 0.17

    An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / 888888 credentials for an ISP.

  • CVE-2021-27157CriFeb 10, 2021
    risk 0.65cvss 9.8epss 0.15

    An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 888888 credentials for an ISP.

  • CVE-2021-27156CriFeb 10, 2021
    risk 0.65cvss 9.8epss 0.15

    An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface.

  • CVE-2021-27155CriFeb 10, 2021
    risk 0.65cvss 9.8epss 0.20

    An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credentials for an ISP.

  • CVE-2021-27154CriFeb 10, 2021
    risk 0.65cvss 9.8epss 0.20

    An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP.