VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 52 of 90
  • CVE-2025-7564HigJul 14, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22. Affected by this issue is some unknown functionality of the file /etc/shadow. The manipulation with the input root:blinkadmin leads to hard-coded credentials. Local access is required…

  • CVE-2024-50593HigNov 8, 2024
    risk 0.51cvss 7.8epss 0.00

    An attacker with local access to the medical office computer can access restricted functions of the Elefant Service tool by using a hard-coded "Hotline" password in the Elefant service binary, which is shipped with the software.

  • CVE-2024-39585HigSep 6, 2024
    risk 0.51cvss 7.9epss 0.00

    Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and…

  • CVE-2024-0865HigJun 12, 2024
    risk 0.51cvss 7.8epss 0.00

    CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.

  • CVE-2023-49221HigJun 7, 2024
    risk 0.51cvss 7.8epss 0.00

    Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and access the service menu, because there is a hard-coded service code.

  • CVE-2023-51588HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Voltronic Power ViewPower Pro MySQL Use of Hard-coded Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Voltronic Power ViewPower Pro. An attacker must first obtain the ability to…

  • CVE-2023-41372HigOct 25, 2023
    risk 0.51cvss 7.8epss 0.00

    The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent…

  • CVE-2023-36623HigJul 5, 2023
    risk 0.51cvss 7.8epss 0.00

    The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC address. This allows a local user to calculate the root password and escalate privileges.

  • CVE-2023-2291HigApr 26, 2023
    risk 0.51cvss 7.8epss 0.01

    Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their…

  • CVE-2023-22429HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow a local attacker to obtain the hard-coded API key via reverse-engineering the application binary.

  • CVE-2022-42973HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions…

  • CVE-2023-21524HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

  • CVE-2022-37710HigNov 7, 2022
    risk 0.51cvss 7.8epss 0.00

    Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt…

  • CVE-2022-26119HigNov 2, 2022
    risk 0.51cvss 7.8epss 0.00

    A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password.

  • CVE-2022-42176HigOct 20, 2022
    risk 0.51cvss 7.8epss 0.00

    In PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access.

  • CVE-2022-31322HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.00

    Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files using SUID flagged executables.

  • CVE-2022-36616HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36615HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36614HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36613HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.