VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 86 of 93
  • CVE-2025-2394MedMay 23, 2025
    risk 0.31cvss —epss 0.00

    Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure.

  • CVE-2025-47730MedMay 8, 2025
    risk 0.31cvss 4.8epss 0.00

    The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.

  • CVE-2024-10451MedNov 25, 2024
    risk 0.31cvss 5.9epss 0.01

    A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosure. In Keycloak 26, sensitive data…

  • CVE-2024-40410MedNov 13, 2024
    risk 0.31cvss 4.8epss 0.00

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.

  • CVE-2023-38535MedMar 13, 2024
    risk 0.31cvss 4.7epss 0.00

    Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys.  

  • CVE-2022-20868MedNov 4, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid…

  • CVE-2021-27503MedAug 2, 2021
    risk 0.31cvss 4.8epss 0.01

    Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: All versions prior to 1.7.5,The application encrypts on the application layer of the communication protocol between the Ypsomed mylife App and mylife Cloud…

  • CVE-2016-3685MedDec 14, 2016
    risk 0.31cvss 4.7epss 0.00

    SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of a hardcoded key in the program code and a…

  • CVE-2026-56269MedJun 24, 2026
    risk 0.30cvss 4.6epss 0.00

    Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/server/src/enterprise/utils/tempTokenUtils.ts when the variable is not configured. This secret derives…

  • CVE-2025-59096MedJan 26, 2026
    risk 0.30cvss —epss 0.00

    The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation.

  • CVE-2025-41696MedDec 9, 2025
    risk 0.30cvss 4.6epss 0.00

    An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.

  • CVE-2025-63433MedNov 24, 2025
    risk 0.30cvss 4.6epss 0.00

    Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application's code. An attacker with the ability to intercept network traffic can use this hardcoded…

  • CVE-2025-41109MedOct 22, 2025
    risk 0.30cvss 4.6epss 0.01

    Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. The vulnerability is due to the lack of authentication mechanisms when establishing connections through these ports. Specifically, with regard to network…

  • CVE-2024-35118MedAug 29, 2024
    risk 0.30cvss 4.6epss 0.00

    IBM MaaS360 for Android 6.31 through 8.60 is using hard coded credentials that can be obtained by a user with physical access to the device.

  • CVE-2024-41689MedJul 26, 2024
    risk 0.30cvss 4.6epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to…

  • CVE-2023-46918MedDec 27, 2023
    risk 0.30cvss 4.6epss 0.00

    Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access to the device.

  • CVE-2023-46711MedDec 26, 2023
    risk 0.30cvss 4.6epss 0.00

    VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the password of a specific product user.

  • CVE-2022-30314MedJul 28, 2022
    risk 0.30cvss 4.6epss 0.00

    Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywell Experion PKS Safety Manager hardcoded credentials issue. The affected components are characterized as: POLO bootloader. The potential impact is: Manipulate…

  • CVE-2017-14014MedMay 1, 2018
    risk 0.30cvss 4.6epss 0.00

    Boston Scientific ZOOM LATITUDE PRM Model 3120 uses a hard-coded cryptographic key to encrypt PHI prior to having it transferred to removable media. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.

  • CVE-2026-79731MedSep 9, 2026
    risk 0.29cvss 4.4epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…