CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,773)
page 68 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-13776 | Hig | 0.46 | 7.1 | 0.00 | Feb 24, 2026 | Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content. This vulnerability has been fixed in version:… | ||
| CVE-2026-2103 | Hig | 0.46 | 7.1 | 0.00 | Feb 6, 2026 | Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and… | ||
| CVE-2025-34501 | Hig | 0.46 | — | 0.00 | Nov 3, 2025 | Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HTTP, Telnet, SMB, X11) are enabled by default. If an attacker can reach these interfaces - most often through local or near-local… | ||
| CVE-2025-58385 | Hig | 0.46 | 7.1 | 0.00 | Sep 26, 2025 | In DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (there is hard-coded and predictable data). | ||
| CVE-2024-48842 | Hig | 0.46 | 7.0 | 0.00 | Sep 17, 2025 | Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions | ||
| CVE-2025-31953 | Hig | 0.46 | 7.1 | 0.00 | Jul 24, 2025 | HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties. | ||
| CVE-2025-5023 | Hig | 0.46 | 7.1 | 0.00 | Jul 10, 2025 | Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication range between the units of the product (measurement… | ||
| CVE-2024-7295 | Hig | 0.46 | 7.1 | 0.00 | Nov 13, 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information. | ||
| CVE-2024-7206 | Hig | 0.46 | — | 0.00 | Oct 8, 2024 | SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via Flash the modified firmware | ||
| CVE-2024-27168 | — | Hig | 0.46 | 7.1 | 0.00 | Jun 14, 2024 | It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the affected products/models/versions, see the reference URL. | |
| CVE-2023-52723 | Hig | 0.46 | 7.1 | 0.01 | Apr 29, 2024 | In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value. | ||
| CVE-2023-42492 | Hig | 0.46 | 7.1 | 0.00 | Oct 25, 2023 | EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key | ||
| CVE-2023-34338 | Hig | 0.46 | 7.1 | 0.00 | Jul 5, 2023 | AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability. | ||
| CVE-2022-3928 | Hig | 0.46 | 7.1 | 0.00 | Jan 5, 2023 | Hardcoded credential is found in affected products' message queue. An attacker that manages to exploit this vulnerability will be able to access data to the internal message queue. This issue affects * FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B,… | ||
| CVE-2021-40342 | Hig | 0.46 | 7.1 | 0.00 | Jan 5, 2023 | In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements that are managed by the affected products versions. This issue… | ||
| CVE-2022-1400 | Hig | 0.46 | 7.1 | 0.01 | Aug 17, 2022 | Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00. | ||
| CVE-2022-22560 | Hig | 0.46 | 7.1 | 0.00 | Apr 12, 2022 | Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. The attacker can exploit this vulnerability to take the switch… | ||
| CVE-2022-22766 | Hig | 0.46 | 7.0 | 0.00 | Feb 11, 2022 | Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access… | ||
| CVE-2020-16258 | Hig | 0.46 | 7.1 | 0.00 | Oct 28, 2020 | Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials. | ||
| CVE-2019-5139 | Hig | 0.46 | 7.1 | 0.00 | Feb 25, 2020 | An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts. |
- risk 0.46cvss 7.1epss 0.00
Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content. This vulnerability has been fixed in version:…
- risk 0.46cvss 7.1epss 0.00
Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and…
- risk 0.46cvss —epss 0.00
Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HTTP, Telnet, SMB, X11) are enabled by default. If an attacker can reach these interfaces - most often through local or near-local…
- risk 0.46cvss 7.1epss 0.00
In DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (there is hard-coded and predictable data).
- risk 0.46cvss 7.0epss 0.00
Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions
- risk 0.46cvss 7.1epss 0.00
HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.
- risk 0.46cvss 7.1epss 0.00
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication range between the units of the product (measurement…
- risk 0.46cvss 7.1epss 0.00
In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.
- risk 0.46cvss —epss 0.00
SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via Flash the modified firmware
- risk 0.46cvss 7.1epss 0.00
It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the affected products/models/versions, see the reference URL.
- risk 0.46cvss 7.1epss 0.01
In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.
- risk 0.46cvss 7.1epss 0.00
EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key
- risk 0.46cvss 7.1epss 0.00
AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.
- risk 0.46cvss 7.1epss 0.00
Hardcoded credential is found in affected products' message queue. An attacker that manages to exploit this vulnerability will be able to access data to the internal message queue. This issue affects * FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B,…
- risk 0.46cvss 7.1epss 0.00
In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements that are managed by the affected products versions. This issue…
- risk 0.46cvss 7.1epss 0.01
Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00.
- risk 0.46cvss 7.1epss 0.00
Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. The attacker can exploit this vulnerability to take the switch…
- risk 0.46cvss 7.0epss 0.00
Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access…
- risk 0.46cvss 7.1epss 0.00
Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.
- risk 0.46cvss 7.1epss 0.00
An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.