VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 59 of 93
  • CVE-2025-56466HigSep 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information.

  • CVE-2025-7342HigAug 17, 2025
    risk 0.49cvss 7.5epss 0.00

    A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when using the Nutanix or VMware OVA providers. These credentials, which allow root access, are disabled at the conclusion of the build.…

  • CVE-2025-38741HigAug 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.

  • CVE-2025-4130HigJul 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable. This issue affects PAVO Pay: before 13.05.2025.

  • CVE-2025-52492HigJul 7, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz, contains hard-coded credentials for the Twilio API. A remote attacker who obtains a copy of the firmware can extract these credentials. This could allow the…

  • CVE-2025-30118HigMar 25, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses the same default credentials for all devices and does not implement proper multi-device authentication, allowing attackers to deny the owner access by…

  • CVE-2025-2343HigMar 16, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability classified as critical was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this vulnerability is an unknown functionality of the component Device Pairing. The manipulation leads to hard-coded credentials. Access to the local network is…

  • CVE-2024-53357HigJan 31, 2025
    risk 0.49cvss 7.5epss 0.01

    Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /api/user/updatealiasroute; (4) delete…

  • CVE-2024-55927HigJan 23, 2025
    risk 0.49cvss 7.6epss 0.00

    A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to predict or forge tokens, leading to unauthorized access to sensitive functions.

  • CVE-2024-11147HigJan 23, 2025
    risk 0.49cvss 7.6epss 0.00

    ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.

  • CVE-2024-54749HigDec 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: this is disputed by the Supplier because the observation only established that a password is present in a firmware image; however,…

  • CVE-2024-41777HigDec 3, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2024-45861HigSep 19, 2024
    risk 0.49cvss 7.5epss 0.00

    Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker to access sensitive information.

  • CVE-2024-41161HigAug 8, 2024
    risk 0.49cvss 7.5epss 0.01

    Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to bypass authentication using hard-coded administrator credentials. These …

  • CVE-2024-33329HigJun 26, 2024
    risk 0.49cvss 7.5epss 0.01

    A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive information.

  • CVE-2024-36496HigJun 24, 2024
    risk 0.49cvss 7.5epss 0.01

    The configuration file is encrypted with a static key derived from a static five-character password which allows an attacker to decrypt this file. The application hashes this five-character password with the outdated and broken MD5 algorithm (no salt) and uses the first five…

  • CVE-2024-32988HigMay 22, 2024
    risk 0.49cvss 7.5epss 0.00

    'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.

  • CVE-2024-4844HigMay 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacker with admin privileges on the ePO server to read the contents of the orion.keystore file, allowing them to access the ePO database…

  • CVE-2024-3544HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to the same network of one of the machines in the HA or Cluster group. This vulnerability has been closed by enhancing LoadMaster partner communications to require…

  • CVE-2024-29966HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.01

    Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vulnerability could allow an unauthenticated attacker full access to the Brocade SANnav appliance.