VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 74 of 93
  • CVE-2014-5431MedMar 26, 2019
    risk 0.44cvss 6.8epss 0.00

    Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contains a hard-coded password, which provides access to basic biomedical information, limited device settings, and network configuration of the WBM, if connected.…

  • CVE-2018-12323MedJun 13, 2018
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easier for physically proximate attackers to login at the console.

  • CVE-2018-9149MedApr 1, 2018
    risk 0.44cvss 6.8epss 0.00

    The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device and uses a USB-to-UART cable to connect the device, he can use the 1234 password for the root account to login to the system.…

  • CVE-2017-12317MedOct 22, 2017
    risk 0.44cvss 6.7epss 0.00

    The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the connector protection…

  • CVE-2017-12239MedSep 29, 2017
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical attacker to access an affected device's operating system. The vulnerability…

  • CVE-2026-50601MedAug 17, 2026
    risk 0.43cvss —epss 0.00

    A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key permitted unauthorized access to internal repositories. An attacker could exploit this access to extract embedded administrative keys and secrets, potentially…

  • CVE-2025-65855MedDec 17, 2025
    risk 0.43cvss 6.6epss 0.00

    The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identical across all devices and does not authenticate update servers or validate firmware signatures. An attacker with brief physical…

  • CVE-2024-33895MedAug 2, 2024
    risk 0.43cvss 6.6epss 0.01

    Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.

  • CVE-2023-34473MedJul 5, 2023
    risk 0.43cvss 6.6epss 0.00

    AMI SPx contains a vulnerability in the BMC where a valid user may cause a use of hard-coded credentials. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.

  • CVE-2022-40263MedNov 4, 2022
    risk 0.43cvss 6.6epss 0.00

    BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and…

  • CVE-2018-17771MedSep 9, 2020
    risk 0.43cvss 6.6epss 0.00

    Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.

  • CVE-2019-9493MedJan 15, 2020
    risk 0.43cvss 6.5epss 0.04

    The MyCar Controls of AutoMobility Distribution Inc., mobile application contains hard-coded admin credentials. A remote unauthenticated attacker may be able to send commands to and retrieve data from a target MyCar unit. This may allow the attacker to learn the location of a…

  • CVE-2026-80170MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2026-77847MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.

  • CVE-2026-49204MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

  • CVE-2026-25600MedJun 1, 2026
    risk 0.42cvss 6.4epss 0.00

    The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption routines, including the function responsible for decrypting credentials stored in the product’s configuration file.…

  • CVE-2026-1233HigApr 4, 2026
    risk 0.42cvss 7.5epss 0.00

    The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials for the vendor's external telemetry…

  • CVE-2026-25601MedApr 1, 2026
    risk 0.42cvss 6.4epss 0.00

    A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic key within the Mx.Web.ComponentModel.dll component. When the option to store domain passwords was enabled, this key was used to…

  • CVE-2025-41710MedMar 10, 2026
    risk 0.42cvss 6.5epss 0.00

    An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges.

  • CVE-2025-33089MedFeb 17, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard coded user credentials.