CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,845)
page 78 of 93| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-30198 | Med | 0.41 | 6.3 | 0.00 | Sep 5, 2025 | ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived. | ||
| CVE-2024-45319 | Med | 0.41 | 6.3 | 0.00 | Dec 5, 2024 | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication. | ||
| CVE-2024-20280 | Med | 0.41 | 6.3 | 0.00 | Oct 16, 2024 | A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption… | ||
| CVE-2024-28990 | Med | 0.41 | 6.3 | 0.00 | Sep 12, 2024 | SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing… | ||
| CVE-2023-34284 | Med | 0.41 | 6.3 | 0.00 | May 3, 2024 | NETGEAR RAX30 Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The… | ||
| CVE-2023-46919 | Med | 0.41 | 6.3 | 0.00 | Dec 27, 2023 | Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K (AES) encryption key. An attacker with physical access to the application's source code or binary can… | ||
| CVE-2023-41030 | Med | 0.41 | 6.3 | 0.01 | Sep 18, 2023 | Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user. | ||
| CVE-2023-3237 | Med | 0.41 | 6.3 | 0.01 | Jun 14, 2023 | A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input admin leads to use of hard-coded password. The exploit has been disclosed to the public and may be… | ||
| CVE-2022-3089 | Med | 0.41 | 6.3 | 0.00 | Feb 13, 2023 | Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user… | ||
| CVE-2021-44464 | Med | 0.41 | 6.3 | 0.01 | Jan 21, 2022 | Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across all instances. An attacker in possession of the password may gain privileges on all installations of this software. | ||
| CVE-2020-2499 | Med | 0.41 | 6.3 | 0.01 | Dec 24, 2020 | A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later. | ||
| CVE-2026-86555 | Med | 0.40 | 6.2 | 0.00 | Sep 20, 2026 | The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it. | ||
| CVE-2026-93970 | — | Hig | 0.40 | 7.3 | 0.01 | Sep 20, 2026 | A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote.… | |
| CVE-2026-93969 | — | Hig | 0.40 | 7.3 | 0.01 | Sep 20, 2026 | A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be carried out remotely. The identifier of the… | |
| CVE-2026-85544 | Med | 0.40 | 6.1 | 0.00 | Sep 10, 2026 | Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, thereby gaining the permission to issue… | ||
| CVE-2026-9260 | Med | 0.40 | 6.2 | 0.00 | Jun 16, 2026 | Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier | ||
| CVE-2025-55449 | Hig | 0.40 | 7.3 | 0.00 | May 8, 2026 | AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT. | ||
| CVE-2025-12708 | Med | 0.40 | 6.2 | 0.00 | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user. | ||
| CVE-2025-33100 | Med | 0.40 | 6.2 | 0.00 | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | ||
| CVE-2025-41380 | Med | 0.40 | — | 0.00 | May 23, 2025 | Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a local user to retrieve the SSH hash string. |
- risk 0.41cvss 6.3epss 0.00
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.
- risk 0.41cvss 6.3epss 0.00
A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication.
- risk 0.41cvss 6.3epss 0.00
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption…
- risk 0.41cvss 6.3epss 0.00
SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing…
- risk 0.41cvss 6.3epss 0.00
NETGEAR RAX30 Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The…
- risk 0.41cvss 6.3epss 0.00
Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K (AES) encryption key. An attacker with physical access to the application's source code or binary can…
- risk 0.41cvss 6.3epss 0.01
Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user.
- risk 0.41cvss 6.3epss 0.01
A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input admin leads to use of hard-coded password. The exploit has been disclosed to the public and may be…
- risk 0.41cvss 6.3epss 0.00
Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user…
- risk 0.41cvss 6.3epss 0.01
Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across all instances. An attacker in possession of the password may gain privileges on all installations of this software.
- risk 0.41cvss 6.3epss 0.01
A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.
- risk 0.40cvss 6.2epss 0.00
The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.
- risk 0.40cvss 7.3epss 0.01
A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote.…
- risk 0.40cvss 7.3epss 0.01
A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be carried out remotely. The identifier of the…
- risk 0.40cvss 6.1epss 0.00
Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, thereby gaining the permission to issue…
- risk 0.40cvss 6.2epss 0.00
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
- risk 0.40cvss 7.3epss 0.00
AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.
- risk 0.40cvss 6.2epss 0.00
IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.
- risk 0.40cvss 6.2epss 0.00
IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
- risk 0.40cvss —epss 0.00
Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a local user to retrieve the SSH hash string.