CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,773)
page 5 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2306 | Cri | 0.65 | 10.0 | 0.00 | Oct 5, 2023 | Qognify NiceVision versions 3.1 and prior are vulnerable to exposing sensitive information using hard-coded credentials. With these credentials an attacker can retrieve information about the cameras, user information, and modify database records. | ||
| CVE-2023-24022 | Cri | 0.65 | 10.0 | 0.02 | Jan 26, 2023 | Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily discovered and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by… | ||
| CVE-2022-45444 | Cri | 0.65 | 10.0 | 0.01 | Jan 18, 2023 | Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select users in the application’s database. This could allow a remote attacker to login to the database with unrestricted access. | ||
| CVE-2022-35413 | Cri | 0.65 | 9.8 | 0.14 | Sep 13, 2022 | WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001. | ||
| CVE-2022-34907 | Cri | 0.65 | 9.8 | 0.16 | Jul 25, 2022 | An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform. | ||
| CVE-2021-40422 | Cri | 0.65 | 10.0 | 0.06 | Apr 14, 2022 | An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability. | ||
| CVE-2021-40519 | Cri | 0.65 | 10.0 | 0.01 | Nov 10, 2021 | Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials. | ||
| CVE-2021-0248 | Cri | 0.65 | 10.0 | 0.01 | Apr 22, 2021 | This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an attacker to take over any instance of an NFX deployment. This issue is only exploitable through administrative interfaces. This… | ||
| CVE-2021-27172 | Cri | 0.65 | 9.8 | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. A hardcoded GEPON password for root is defined inside /etc/init.d/system-config.sh. | ||
| CVE-2021-27169 | Cri | 0.65 | 9.8 | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome AN5506-04-FA devices with firmware RP2631. There is a gepon password for the gepon account. | ||
| CVE-2021-27168 | Cri | 0.65 | 9.8 | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. There is a 6GFJdY4aAuUKJjdtSn7d password for the rdsadmin account. | ||
| CVE-2021-27167 | Cri | 0.65 | 9.8 | 0.15 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. There is a password of four hexadecimal characters for the admin account. These characters are generated in init_3bb_password in libci_adaptation_layer.so. | ||
| CVE-2021-27166 | Cri | 0.65 | 9.8 | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The password for the enable command is gpon. | ||
| CVE-2021-27165 | Cri | 0.65 | 9.8 | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The telnet daemon on port 23/tcp can be abused with the gpon/gpon credentials. | ||
| CVE-2021-27161 | Cri | 0.65 | 9.8 | 0.17 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 1234 credentials for an ISP. | ||
| CVE-2021-27160 | Cri | 0.65 | 9.8 | 0.17 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / 888888 credentials for an ISP. | ||
| CVE-2021-27157 | Cri | 0.65 | 9.8 | 0.15 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 888888 credentials for an ISP. | ||
| CVE-2021-27156 | Cri | 0.65 | 9.8 | 0.15 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface. | ||
| CVE-2021-27155 | Cri | 0.65 | 9.8 | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credentials for an ISP. | ||
| CVE-2021-27154 | Cri | 0.65 | 9.8 | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP. |
- risk 0.65cvss 10.0epss 0.00
Qognify NiceVision versions 3.1 and prior are vulnerable to exposing sensitive information using hard-coded credentials. With these credentials an attacker can retrieve information about the cameras, user information, and modify database records.
- risk 0.65cvss 10.0epss 0.02
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily discovered and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by…
- risk 0.65cvss 10.0epss 0.01
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select users in the application’s database. This could allow a remote attacker to login to the database with unrestricted access.
- risk 0.65cvss 9.8epss 0.14
WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.
- risk 0.65cvss 9.8epss 0.16
An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.
- risk 0.65cvss 10.0epss 0.06
An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.
- risk 0.65cvss 10.0epss 0.01
Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials.
- risk 0.65cvss 10.0epss 0.01
This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an attacker to take over any instance of an NFX deployment. This issue is only exploitable through administrative interfaces. This…
- risk 0.65cvss 9.8epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. A hardcoded GEPON password for root is defined inside /etc/init.d/system-config.sh.
- risk 0.65cvss 9.8epss 0.20
An issue was discovered on FiberHome AN5506-04-FA devices with firmware RP2631. There is a gepon password for the gepon account.
- risk 0.65cvss 9.8epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. There is a 6GFJdY4aAuUKJjdtSn7d password for the rdsadmin account.
- risk 0.65cvss 9.8epss 0.15
An issue was discovered on FiberHome HG6245D devices through RP2613. There is a password of four hexadecimal characters for the admin account. These characters are generated in init_3bb_password in libci_adaptation_layer.so.
- risk 0.65cvss 9.8epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. The password for the enable command is gpon.
- risk 0.65cvss 9.8epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. The telnet daemon on port 23/tcp can be abused with the gpon/gpon credentials.
- risk 0.65cvss 9.8epss 0.17
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 1234 credentials for an ISP.
- risk 0.65cvss 9.8epss 0.17
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / 888888 credentials for an ISP.
- risk 0.65cvss 9.8epss 0.15
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 888888 credentials for an ISP.
- risk 0.65cvss 9.8epss 0.15
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface.
- risk 0.65cvss 9.8epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credentials for an ISP.
- risk 0.65cvss 9.8epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP.