VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 57 of 93
  • CVE-2023-39421HigSep 7, 2023
    risk 0.50cvss 7.7epss 0.00

    The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.

  • CVE-2023-31173HigAug 31, 2023
    risk 0.50cvss 7.7epss 0.00

    Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Windows allows Authentication Bypass. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue affects SEL-5037 SEL Grid…

  • CVE-2023-21652HigAug 8, 2023
    risk 0.50cvss 7.7epss 0.00

    Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.

  • CVE-2022-34906HigJul 25, 2022
    risk 0.50cvss 7.5epss 0.11

    A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.

  • CVE-2021-27142HigFeb 10, 2021
    risk 0.50cvss 7.5epss 0.16

    An issue was discovered on FiberHome HG6245D devices through RP2613. The web management is done over HTTPS, using a hardcoded private key that has 0777 permissions.

  • CVE-2017-7927HigMay 6, 2017
    risk 0.50cvss 7.3epss 0.18

    A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX,…

  • CVE-2016-5645HigAug 24, 2016
    risk 0.50cvss 7.3epss 0.30

    Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote attackers to load arbitrary firmware updates by leveraging knowledge of this…

  • CVE-2026-86520HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

  • CVE-2026-79950HigSep 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2026-79740HigSep 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2026-79738HigSep 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2026-74892HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.00

    openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.

  • CVE-2026-13460HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.

  • CVE-2026-49007HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.

  • CVE-2025-15628HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept…

  • CVE-2026-13463HigJul 28, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.

  • CVE-2026-56266HigJun 22, 2026
    risk 0.49cvss 8.6epss 0.00

    Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4…

  • CVE-2026-50213HigJun 4, 2026
    risk 0.49cvss 7.5epss 0.00

    The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.

  • CVE-2019-25722HigJun 2, 2026
    risk 0.49cvss 7.6epss 0.00

    Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denial-of-service vulnerability that allows local and remote attackers to compromise device integrity across all software versions. A…

  • CVE-2020-37220HigMay 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can query the /api/system/deviceinfo endpoint without authentication to extract the…