VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 74 of 89
  • CVE-2016-10928HigAug 22, 2019
    risk 0.42cvss 7.5epss 0.02

    The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.

  • CVE-2019-11946MedJun 5, 2019
    risk 0.42cvss 6.5epss 0.01

    A remote credential disclosure vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-10851MedMay 23, 2019
    risk 0.42cvss 6.5epss 0.01

    Computrols CBAS 18.0.0 has hard-coded encryption keys.

  • CVE-2018-17919MedOct 10, 2018
    risk 0.42cvss 6.5epss 0.01

    All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video streams.

  • CVE-2018-0039MedJul 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Grafana or exploit other weaknesses or…

  • CVE-2018-8870MedJul 3, 2018
    risk 0.42cvss 6.4epss 0.00

    Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can remove the case of the device, connect to the debug port, and use the password to gain privileged access to the operating system.

  • CVE-2026-21404MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful…

  • CVE-2026-2635HigFeb 20, 2026
    risk 0.41cvss 7.3epss 0.01

    MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2025-0642MedOct 2, 2025
    risk 0.41cvss 6.3epss 0.00

    Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Software and Consulting Ltd. Co. Assist allows Excavation, Authentication Bypass. This issue affects Assist: through 10.02.2025.

  • CVE-2025-30200MedSep 5, 2025
    risk 0.41cvss 6.3epss 0.00

    ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.

  • CVE-2025-30198MedSep 5, 2025
    risk 0.41cvss 6.3epss 0.00

    ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

  • CVE-2024-45319MedDec 5, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication.

  • CVE-2024-20280MedOct 16, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption…

  • CVE-2024-28990MedSep 12, 2024
    risk 0.41cvss 6.3epss 0.00

    SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing…

  • CVE-2023-34284MedMay 3, 2024
    risk 0.41cvss 6.3epss 0.00

    NETGEAR RAX30 Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-46919MedDec 27, 2023
    risk 0.41cvss 6.3epss 0.00

    Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K (AES) encryption key. An attacker with physical access to the application's source code or binary can…

  • CVE-2023-41030MedSep 18, 2023
    risk 0.41cvss 6.3epss 0.01

    Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user.

  • CVE-2023-3237MedJun 14, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input admin leads to use of hard-coded password. The exploit has been disclosed to the public and may be…

  • CVE-2022-3089MedFeb 13, 2023
    risk 0.41cvss 6.3epss 0.00

    Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user…

  • CVE-2021-44464MedJan 21, 2022
    risk 0.41cvss 6.3epss 0.01

    Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across all instances. An attacker in possession of the password may gain privileges on all installations of this software.