VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 9 of 93
  • CVE-2016-20026CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.01

    ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives…

  • CVE-2026-28255CriMar 12, 2026
    risk 0.64cvss 9.8epss 0.00

    A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.

  • CVE-2026-24448CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.

  • CVE-2026-29119CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.00

    International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these undocumented credentials to access the satellite system directly via…

  • CVE-2026-28778CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd` user account. A remote unauthenticated attacker can log in via FTP using these credentials. Because the `xd` user has write…

  • CVE-2026-28777CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.00

    International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker…

  • CVE-2026-28776CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.00

    International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can use these trivial, undocumented credentials to access the system via SSH. While initially dropped…

  • CVE-2026-27507CriFeb 24, 2026
    risk 0.64cvss 9.8epss 0.00

    Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative credentials that cannot be changed by users. Knowledge of these credentials allows full administrative access to the device.

  • CVE-2025-67304CriFeb 19, 2026
    risk 0.64cvss 9.8epss 0.01

    In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network on TCP port 5432. An attacker can use the hardcoded…

  • CVE-2026-23647CriFeb 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user accounts, including accounts with administrative privileges, were found to…

  • CVE-2026-26218CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.00

    newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default…

  • CVE-2025-69971CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.02

    FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin tokens and bypass authentication to gain full administrative…

  • CVE-2026-25202CriFeb 2, 2026
    risk 0.64cvss 9.8epss 0.00

    The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1.

  • CVE-2026-1221CriJan 20, 2026
    risk 0.64cvss 9.8epss 0.01

    PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to the database using hardcoded database credentials stored in the firmware.

  • CVE-2021-47796CriJan 16, 2026
    risk 0.64cvss 9.8epss 0.01

    Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attackers to access a Linux shell. Attackers can connect to port 23 using the default credential to execute arbitrary commands on the camera's operating system.

  • CVE-2023-53983CriDec 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.

  • CVE-2022-50696CriDec 30, 2025
    risk 0.64cvss 9.8epss 0.01

    SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and…

  • CVE-2019-25241CriDec 24, 2025
    risk 0.64cvss 9.8epss 0.01

    FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands…

  • CVE-2018-25138CriDec 24, 2025
    risk 0.64cvss 9.8epss 0.01

    FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to multiple camera interfaces using…

  • CVE-2025-33222CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and data tampering.