CWE-259
194 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use of Hard-coded Password
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
CVEs (194)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
CyberPower PowerPanel business
application code contains a hard-coded JWT signing key. This could
result in an attacker forging JWT tokens to bypass authentication. |
An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt. |
1Siemens 1Simatic Cn 4100 Firmware Jun 17, 2026 May 14, 2024 N/A· v4 10.0 CRITICAL· v3 N/A· v2 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default...Show more |
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root. |
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample. |
D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DCS-8300LHV2 IP cameras. Auth...Show more |
1Dlink 2Dap 1360 Firmware Dap 2020 FirmwareJun 17, 2026 May 3, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1360 routers. Authenticatio...Show more |
Use of hard-coded password in the GMS ECM endpoint leading to authentication bypass vulnerability.
This issue affects GMS: 9.3.4 and earlier versions.
|
The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default for forms and SQL connections. |
DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control. |
1Netapp 1Ontap Select Deploy Administration Utility Jun 17, 2026 Apr 17, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentia...Show more |
1Mitel 146905 Firmware 6910 Firmware6915 Firmware+11 moreJun 17, 2026 Apr 8, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password). |
Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by def...Show more |
1Nec 59Aterm Cr2500p Firmware Aterm Mr01ln FirmwareAterm Mr02ln Firmware+56 moreJun 17, 2026 Mar 28, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Use of Hard-coded Password in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF...Show more |
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability |
The Chirp Access app contains a hard-coded password, BEACON_PASSWORD. An attacker within Bluetooth range could change configuration settings within the Bluetooth beacon, effectively disabling the application's ability to...Show more |
Unitronics Unistream Unilogic – Versions prior to 1.35.227 -
CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device's Firmware
|
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or enc...Show more |
The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The console allows attackers with physical access to the MIB3 unit to gain full...Show more |
SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function. |