VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 72 of 89
  • CVE-2025-41710MedMar 10, 2026
    risk 0.42cvss 6.5epss 0.00

    An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges.

  • CVE-2025-33089MedFeb 17, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard coded user credentials.

  • CVE-2026-0622MedJan 20, 2026
    risk 0.42cvss 6.5epss 0.00

    Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset

  • CVE-2025-4633MedMay 30, 2025
    risk 0.42cvss 6.5epss 0.00

    Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an unauthenticated malicious actor to log in via the web portal

  • CVE-2025-36572MedMay 28, 2025
    risk 0.42cvss 6.5epss 0.00

    Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain…

  • CVE-2025-48414MedMay 21, 2025
    risk 0.42cvss 6.5epss 0.00

    There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functionality and are likely intended for debugging during development and provides an additional attack…

  • CVE-2025-45746MedMay 13, 2025
    risk 0.42cvss 6.5epss 0.00

    In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically only accessible from a local…

  • CVE-2025-30109MedMar 18, 2025
    risk 0.42cvss 6.5epss 0.00

    In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded credentials that allow an attacker on the local Wi-Fi network to access API endpoints and retrieve sensitive device information,…

  • CVE-2024-50690MedJan 24, 2025
    risk 0.42cvss 6.5epss 0.00

    SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmware updates.

  • CVE-2024-28778MedJan 7, 2025
    risk 0.42cvss 6.5epss 0.01

    IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization.

  • CVE-2024-53614MedDec 4, 2024
    risk 0.42cvss 6.5epss 0.01

    A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevated privileges.

  • CVE-2024-50377MedNov 26, 2024
    risk 0.42cvss 6.5epss 0.00

    A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability is associated to the backup configuration functionality…

  • CVE-2024-5764MedOct 23, 2024
    risk 0.42cvss 6.5epss 0.00

    Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others). The affected…

  • CVE-2024-23958MedSep 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Autel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations.…

  • CVE-2023-41611MedSep 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.

  • CVE-2024-36049MedMay 24, 2024
    risk 0.42cvss 6.5epss 0.00

    Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list of usernames and passwords from the database server, using an unencrypted connection. This allows attackers in a machine-in-the-middle position read and write…

  • CVE-2023-39482MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Softing Secure Integration Server. Although authentication is required to…

  • CVE-2024-22083MedMar 20, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. A hardcoded backdoor session ID exists that can be used for further access to the device, including reconfiguration tasks.

  • CVE-2023-50948MedJan 8, 2024
    risk 0.42cvss 6.5epss 0.01

    IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 275671.

  • CVE-2023-49228MedDec 28, 2023
    risk 0.42cvss 6.4epss 0.00

    An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root.