VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 72 of 93
  • CVE-2026-5522MedSep 4, 2026
    risk 0.44cvss 6.7epss 0.00

    IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2026-73847MedAug 14, 2026
    risk 0.44cvss 6.8epss 0.00

    Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently…

  • CVE-2025-59095MedJan 26, 2026
    risk 0.44cvss —epss 0.00

    The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is the function "EncryptAndDecrypt" in the library Kaba.EXOS.common.dll. This algorithm uses a simple XOR encryption technique combined with a cryptographic key…

  • CVE-2025-66237MedDec 4, 2025
    risk 0.44cvss 6.7epss 0.00

    DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system commands on the host.

  • CVE-2025-54465MedAug 13, 2025
    risk 0.44cvss —epss 0.00

    This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and analyzing the binary data to retrieve the…

  • CVE-2025-8231MedJul 27, 2025
    risk 0.44cvss 6.8epss 0.01

    A vulnerability, which was classified as critical, has been found in D-Link DIR-890L up to 111b04. This issue affects some unknown processing of the file rgbin of the component UART Port. The manipulation leads to hard-coded credentials. It is possible to launch the attack on…

  • CVE-2025-52363MedJul 14, 2025
    risk 0.44cvss 6.8epss 0.00

    Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image can extract and attempt to crack the root password hash, potentially obtaining administrative access

  • CVE-2025-5751MedJun 6, 2025
    risk 0.44cvss 6.8epss 0.00

    WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of WOLFBOX Level 2 EV Charger. Authentication is not required to…

  • CVE-2025-27488MedMay 13, 2025
    risk 0.44cvss 6.7epss 0.00

    Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.

  • CVE-2021-22126MedMar 17, 2025
    risk 0.44cvss 6.7epss 0.00

    A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenticated attacker to connect to the managed Access Point (Meru AP and FortiAP-U) as root using the…

  • CVE-2022-27600MedDec 19, 2024
    risk 0.44cvss 6.8epss 0.01

    An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the…

  • CVE-2024-8449MedSep 30, 2024
    risk 0.44cvss 6.8epss 0.00

    Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.

  • CVE-2024-31798MedAug 15, 2024
    risk 0.44cvss 6.8epss 0.00

    Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices

  • CVE-2024-29960MedApr 19, 2024
    risk 0.44cvss 6.8epss 0.00

    In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Brocade SAnnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH…

  • CVE-2023-40146MedApr 17, 2024
    risk 0.44cvss 6.8epss 0.01

    A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials…

  • CVE-2024-1344MedFeb 19, 2024
    risk 0.44cvss 6.8epss 0.00

    Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read and extract the username and password from the database of 'LOF_service.exe' and 'LaborOfficeFree.exe' located in the '%programfiles(x86)%\LaborOfficeFree\'…

  • CVE-2023-50124MedJan 11, 2024
    risk 0.44cvss 6.8epss 0.00

    Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain design choices, an attacker can unlock the Flient Smart Door Lock by replacing the fingerprint that is stored on the scanner.

  • CVE-2022-22466MedOct 23, 2023
    risk 0.44cvss 6.8epss 0.01

    IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 225222.

  • CVE-2023-43637HigSep 21, 2023
    risk 0.44cvss 7.8epss 0.00

    Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the last 16 bytes predetermined to be "arfoobarfoobarfo". This issue happens because "deriveVaultKey" calls "retrieveCloudKey" (which will always return…

  • CVE-2022-3744MedAug 23, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.