VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 78 of 93
  • CVE-2025-30198MedSep 5, 2025
    risk 0.41cvss 6.3epss 0.00

    ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

  • CVE-2024-45319MedDec 5, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication.

  • CVE-2024-20280MedOct 16, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption…

  • CVE-2024-28990MedSep 12, 2024
    risk 0.41cvss 6.3epss 0.00

    SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing…

  • CVE-2023-34284MedMay 3, 2024
    risk 0.41cvss 6.3epss 0.00

    NETGEAR RAX30 Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-46919MedDec 27, 2023
    risk 0.41cvss 6.3epss 0.00

    Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K (AES) encryption key. An attacker with physical access to the application's source code or binary can…

  • CVE-2023-41030MedSep 18, 2023
    risk 0.41cvss 6.3epss 0.01

    Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user.

  • CVE-2023-3237MedJun 14, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input admin leads to use of hard-coded password. The exploit has been disclosed to the public and may be…

  • CVE-2022-3089MedFeb 13, 2023
    risk 0.41cvss 6.3epss 0.00

    Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user…

  • CVE-2021-44464MedJan 21, 2022
    risk 0.41cvss 6.3epss 0.01

    Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across all instances. An attacker in possession of the password may gain privileges on all installations of this software.

  • CVE-2020-2499MedDec 24, 2020
    risk 0.41cvss 6.3epss 0.01

    A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.

  • CVE-2026-86555MedSep 20, 2026
    risk 0.40cvss 6.2epss 0.00

    The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.

  • CVE-2026-93970HigSep 20, 2026
    risk 0.40cvss 7.3epss 0.01

    A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote.…

  • CVE-2026-93969HigSep 20, 2026
    risk 0.40cvss 7.3epss 0.01

    A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be carried out remotely. The identifier of the…

  • CVE-2026-85544MedSep 10, 2026
    risk 0.40cvss 6.1epss 0.00

    Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, thereby gaining the permission to issue…

  • CVE-2026-9260MedJun 16, 2026
    risk 0.40cvss 6.2epss 0.00

    Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

  • CVE-2025-55449HigMay 8, 2026
    risk 0.40cvss 7.3epss 0.00

    AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.

  • CVE-2025-12708MedMar 25, 2026
    risk 0.40cvss 6.2epss 0.00

    IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.

  • CVE-2025-33100MedAug 18, 2025
    risk 0.40cvss 6.2epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2025-41380MedMay 23, 2025
    risk 0.40cvss —epss 0.00

    Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a local user to retrieve the SSH hash string.