VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 9 of 89
  • CVE-2026-26218CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.00

    newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default…

  • CVE-2025-69971CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.02

    FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin tokens and bypass authentication to gain full administrative…

  • CVE-2026-25202CriFeb 2, 2026
    risk 0.64cvss 9.8epss 0.00

    The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1.

  • CVE-2026-1221CriJan 20, 2026
    risk 0.64cvss 9.8epss 0.00

    PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to the database using hardcoded database credentials stored in the firmware.

  • CVE-2021-47796CriJan 16, 2026
    risk 0.64cvss 9.8epss 0.01

    Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attackers to access a Linux shell. Attackers can connect to port 23 using the default credential to execute arbitrary commands on the camera's operating system.

  • CVE-2023-53983CriDec 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.

  • CVE-2022-50696CriDec 30, 2025
    risk 0.64cvss 9.8epss 0.01

    SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and…

  • CVE-2019-25241CriDec 24, 2025
    risk 0.64cvss 9.8epss 0.01

    FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands…

  • CVE-2018-25138CriDec 24, 2025
    risk 0.64cvss 9.8epss 0.01

    FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to multiple camera interfaces using…

  • CVE-2025-33222CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and data tampering.

  • CVE-2025-67418CriDec 22, 2025
    risk 0.64cvss 9.8epss 0.00

    ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remote attacker can log in to the administrative panel using these default credentials, resulting in…

  • CVE-2025-56157CriDec 18, 2025
    risk 0.64cvss 9.8epss 0.01

    Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version…

  • CVE-2025-36752CriDec 13, 2025
    risk 0.64cvss 9.8epss 0.00

    Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all…

  • CVE-2025-36747CriDec 13, 2025
    risk 0.64cvss 9.8epss 0.00

    ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious…

  • CVE-2025-65823CriDec 10, 2025
    risk 0.64cvss 9.8epss 0.00

    The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi network, they could gain unauthorized access to the Wi-Fi network of…

  • CVE-2025-29268CriDec 4, 2025
    risk 0.64cvss 9.8epss 0.08

    ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.

  • CVE-2025-6950CriOct 17, 2025
    risk 0.64cvss epss 0.01

    An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated…

  • CVE-2025-10850CriOct 16, 2025
    risk 0.64cvss 9.8epss 0.01

    The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password in the 'fb_ajax_login_or_register' function and in the 'google_ajax_login_or_register' function. This makes it…

  • CVE-2025-34223CriSep 29, 2025
    risk 0.64cvss 9.8epss 0.01

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) contain a default admin account and an installation‑time endpoint at `/admin/query/update_database.php` that can be…

  • CVE-2025-34196CriSep 29, 2025
    risk 0.64cvss 9.8epss 0.00

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments) contain a hardcoded private key for the PrinterLogic Certificate Authority (CA) and a hardcoded password in product…