VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 50 of 90
  • CVE-2019-7212HigApr 24, 2019
    risk 0.53cvss 8.2epss 0.01

    SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.

  • CVE-2019-3710HigMar 28, 2019
    risk 0.53cvss 8.1epss 0.01

    Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying application using undocumented, pre-installed X.509v3 key/certificate pairs. An unauthenticated remote attacker with the knowledge of the default keys may potentially…

  • CVE-2019-6499HigJan 21, 2019
    risk 0.53cvss 8.1epss 0.01

    Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could potentially be exploited by malicious users to compromise the affected system.

  • CVE-2018-9083HigNov 27, 2018
    risk 0.53cvss 8.1epss 0.01

    In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.

  • CVE-2018-17896HigOct 12, 2018
    risk 0.53cvss 8.1epss 0.01

    Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can…

  • CVE-2016-0235HigMar 12, 2018
    risk 0.53cvss 8.2epss 0.00

    IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB systems. IBM X-Force ID: 110326.

  • CVE-2017-12724HigFeb 15, 2018
    risk 0.53cvss 8.1epss 0.01

    A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The FTP server on the pump contains hardcoded credentials, which are not fully initialized. The FTP server is only accessible if the…

  • CVE-2017-12350HigNov 16, 2017
    risk 0.53cvss 8.2epss 0.00

    A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected virtual appliance with root privileges. The vulnerability is due to the presence of default, static user credentials for an…

  • CVE-2017-14116HigSep 3, 2017
    risk 0.53cvss 8.1epss 0.03

    The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver https service with the tech account and an empty password, which allows remote attackers to obtain root privileges by establishing a…

  • CVE-2017-14115HigSep 3, 2017
    risk 0.53cvss 8.1epss 0.04

    The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanent-enable WAN SSH logins to the remotessh account with the 5SaP9I26 password, which allows remote attackers to access a "Terminal shell v1.0"…

  • CVE-2017-7648HigApr 10, 2017
    risk 0.53cvss 8.1epss 0.02

    Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

  • CVE-2016-10125HigJan 9, 2017
    risk 0.53cvss 8.1epss 0.01

    D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session.

  • CVE-2026-48031CriAug 3, 2026
    risk 0.52cvss 9.1epss 0.00

    go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public repository forge tokens for arbitrary…

  • CVE-2025-57579HigSep 12, 2025
    risk 0.52cvss 8.0epss 0.01

    An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password

  • CVE-2025-57578HigSep 12, 2025
    risk 0.52cvss 8.0epss 0.00

    An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password

  • CVE-2025-57577HigSep 12, 2025
    risk 0.52cvss 8.0epss 0.01

    An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "product lines enforce or clearly prompt users to change any initial credentials upon first use. At most, this would be a…

  • CVE-2025-34509HigJun 17, 2025
    risk 0.52cvss 7.5epss 0.55

    Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this…

  • CVE-2025-27255HigMar 10, 2025
    risk 0.52cvss 8.0epss 0.00

    Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code.

  • CVE-2024-52789HigNov 19, 2024
    risk 0.52cvss 8.0epss 0.00

    Tenda W30E v2.0 V16.01.0.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

  • CVE-2024-52788HigNov 19, 2024
    risk 0.52cvss 8.0epss 0.00

    Tenda W9 v1.0.0.7(4456) was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.