VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 65 of 89
  • CVE-2021-23233HigJan 21, 2022
    risk 0.48cvss 7.3epss 0.01

    Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical…

  • CVE-2021-45521HigDec 26, 2021
    risk 0.48cvss 7.4epss 0.00

    Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.

  • CVE-2021-32521HigJul 7, 2021
    risk 0.48cvss 7.3epss 0.01

    Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate privileges. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

  • CVE-2021-33540HigJun 25, 2021
    risk 0.48cvss 7.3epss 0.01

    In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.

  • CVE-2021-31477HigJun 16, 2021
    risk 0.48cvss 7.3epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware and filesystem of the device. The firmware and…

  • CVE-2021-21979HigMar 3, 2021
    risk 0.48cvss 7.3epss 0.01

    In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r108 for Laravel 7 and 8.5.11-debian-10-r0 for Laravel 8, the file /tmp/app/.env is generated at the time that the docker image bitnami/laravel was built, and…

  • CVE-2019-7279HigJul 1, 2019
    risk 0.48cvss 7.3epss 0.02

    Optergy Proton/Enterprise devices have Hard-coded Credentials.

  • CVE-2018-18979HigMay 6, 2019
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded initialization vector. Extraction of the initialization vector is necessary for deciphering communications between this application and the backend…

  • CVE-2018-18978HigMay 6, 2019
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption key. Extraction of the encryption key is necessary for deciphering communications between this application and the backend server. This, in…

  • CVE-2018-15360HigAug 17, 2018
    risk 0.48cvss 7.3epss 0.02

    An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0.

  • CVE-2018-10966HigJun 5, 2018
    risk 0.48cvss 7.3epss 0.02

    An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of the account they wish to take over, and re-sign it using the…

  • CVE-2018-10813HigJun 5, 2018
    risk 0.48cvss 7.3epss 0.01

    In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of…

  • CVE-2018-10328HigApr 24, 2018
    risk 0.48cvss 7.4epss 0.01

    Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote attackers to view the RTSP video stream.

  • CVE-2017-12726HigFeb 15, 2018
    risk 0.48cvss 7.3epss 0.01

    A Use of Hard-coded Password issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. Telnet on the pump uses hardcoded credentials, which can be used if the pump is configured to allow external communications. Smiths…

  • CVE-2017-9956HigSep 26, 2017
    risk 0.48cvss 7.3epss 0.01

    An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains a hard-coded valid session. An attacker can use that session ID as part of the HTTP cookie of a web request, resulting in…

  • CVE-2026-6374HigAug 10, 2026
    risk 0.47cvss 7.3epss 0.00

    Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executable. This issue affects WAH7601: through 20.07.2026.

  • CVE-2026-5667HigJun 17, 2026
    risk 0.47cvss epss 0.00

    Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside…

  • CVE-2026-8876HigJun 3, 2026
    risk 0.47cvss 7.3epss 0.00

    Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These keys decrypt crisis alert keyword data and intervention site data.

  • CVE-2026-36538HigMay 27, 2026
    risk 0.47cvss 7.3epss 0.00

    Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account is set to the trivially weak value root, allowing an attacker with access to the device to authenticate as root and gain full control of the…

  • CVE-2026-8032HigMay 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of the file /cdemos/echs/priv/echs.js. This manipulation of the argument ADMIN_KEY causes hard-coded credentials. The attack is possible to be carried out…