← Back
CWE-259

194 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Use of Hard-coded Password

The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

JSON object

Loading...

CVEs (194)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1A3000ru Firmware
Jun 17, 2026
Jul 28, 2024
5.1 MEDIUM· v4
8.8 HIGH· v3
2.7 LOW· v2
A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini. The manipulation leads to use of hard-coded...Show more
A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini. The manipulation leads to use of hard-coded password. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272591. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Totolink
1A3600r Firmware
Jun 17, 2026
Jul 28, 2024
5.1 MEDIUM· v4
8.8 HIGH· v3
4.9 MEDIUM· v2
A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been rated as critical. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. Th...Show more
A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been rated as critical. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. The exploit has been disclosed to the public and may be used. The identifier VDB-272573 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Totolink
1A3300r Firmware
Jun 17, 2026
Jul 28, 2024
2.0 LOW· v4
4.7 MEDIUM· v3
1.0 LOW· v2
A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/shadow.sample. The manipulation leads to...Show more
A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-272569 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Adtran
1Sdg Smartos
Jun 17, 2026
Jul 24, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account whose password is based on the devices MAC address. All of the devices i...Show more
AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account whose password is based on the devices MAC address. All of the devices internet interfaces share a similar MAC address that only varies in their final octet. This allows network-adjacent attackers to derive the support user's SSH password by decrementing the final octet of the connected gateway address or via the BSSID. An attacker can then execute arbitrary OS commands with root-level privileges. NOTE: The vendor states that there is no intended functionality allowing an attacker to execute arbitrary OS Commands with root-level privileges. The vendor also states that this issue was fixed in SmartOS 12.5.5.1.Show less
1Zkteco
1Zkbio Cvsecurity
Jun 17, 2026
Jul 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.
1Level1
1Wbr 6013 Firmware
Jun 17, 2026
Jul 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.
1Myscada
1Mypro
Jun 17, 2026
Jul 2, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
1H3c
1Magic R230 Firmware
Jun 17, 2026
Jun 24, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
-
-
Jun 17, 2026
Jun 18, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A hard-coded password in the FileCatalyst TransferAgent can be found which can be used to unlock the keystore from which contents may be read out, for example, the private key for certificates. Exploit of this vulnerabil...Show more
A hard-coded password in the FileCatalyst TransferAgent can be found which can be used to unlock the keystore from which contents may be read out, for example, the private key for certificates. Exploit of this vulnerability could lead to a machine-in-the-middle (MiTM) attack against users of the agent. This issue affects all versions of FileCatalyst Direct from 3.8.10 Build 138 and earlier and all versions of FileCatalyst Workflow from 5.1.6 Build 130 and earlier.Show less
1Trendnet
1Tew 814dap Firmware
Jun 17, 2026
Jun 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
-
-
Jun 17, 2026
Jun 14, 2024
N/A· v4
9.4 CRITICAL· v3
N/A· v2
Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also be used to login to the administration panel and to pe...Show more
Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also be used to login to the administration panel and to perform privileged actions.Show less
-
-
Jun 17, 2026
Jun 14, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Toshiba printers contain hardcoded credentials. As for the affected products/models/versions, see the reference URL.
-
-
Jun 17, 2026
Jun 11, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even ex...Show more
A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.Show less
1Estomed
1Simple Care
Jun 17, 2026
Jun 10, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estome...Show more
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simple Care software in all versions. The software is no longer supported.Show less
1Dreryk
1Gabinet
Jun 17, 2026
Jun 10, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet...Show more
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet software versions from 7.0.0.0 through 9.17.0.0.Show less
1Eurosoft
1Przychodnia
Jun 17, 2026
Jun 10, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Euroso...Show more
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia software before version 20240417.001 (from that version vulnerability is fixed).Show less
1Honeywell
1Lenels2 Netbox
Jun 17, 2026
May 30, 2024
8.8 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypass authentication requirements.
1Totolink
1Cp900l Firmware
Jul 9, 2026
May 24, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
-
-
Jun 17, 2026
May 23, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.22.6. This is due to the use of hardcoded credent...Show more
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.22.6. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to modify plugin settings, delete posts, modify post titles, and upload images.Show less
1Cyberpower
1Powerpanel
Jun 17, 2026
May 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges.