← Back
CWE-259

194 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Use of Hard-coded Password

The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

JSON object

Loading...

CVEs (194)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cyberpower
1Powerpanel
Jun 17, 2026
May 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.
1Linqi
1Linqi
Jun 17, 2026
May 14, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.
1Siemens
1Simatic Cn 4100 Firmware
Jun 17, 2026
May 14, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default...Show more
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who manages to crack the password hash gains root access to the device.Show less
1Totolink
1Cp450 Firmware
Jun 17, 2026
May 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
1Totolink
1Ex200 Firmware
Jun 17, 2026
May 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
1Dlink
1Dcs 8300lhv2 Firmware
Jun 17, 2026
May 3, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DCS-8300LHV2 IP cameras. Auth...Show more
D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DCS-8300LHV2 IP cameras. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the ONVIF API. The issue results from the use of a hardcoded PIN. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-21492.Show less
1Dlink
2Dap 1360 Firmware
Dap 2020 Firmware
Jun 17, 2026
May 3, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1360 routers. Authenticatio...Show more
D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of login requests to the web-based user interface. The firmware contains hard-coded default credentials. An attacker can leverage this vulnerability to bypass authentication on the system. . Was ZDI-CAN-18455.Show less
-
-
Jun 17, 2026
May 1, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Use of hard-coded password in the GMS ECM endpoint leading to authentication bypass vulnerability. This issue affects GMS: 9.3.4 and earlier versions.
1Logint
1Lomag Warehouse Management
Jun 17, 2026
May 1, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default for forms and SQL connections.
-
-
Jun 17, 2026
Apr 19, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control.
1Netapp
1Ontap Select Deploy Administration Utility
Jun 17, 2026
Apr 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentia...Show more
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentials. Show less
1Mitel
146905 Firmware
6910 Firmware6915 Firmware+11 more
Jun 17, 2026
Apr 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
-
-
Jun 17, 2026
Apr 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by def...Show more
Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default.Show less
1Nec
59Aterm Cr2500p Firmware
Aterm Mr01ln FirmwareAterm Mr02ln Firmware+56 more
Jun 17, 2026
Mar 28, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Use of Hard-coded Password in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF...Show more
Use of Hard-coded Password in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to execute an arbitrary OS command via the internet.Show less
1Microsoft
1Edge
Jun 17, 2026
Mar 21, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
-
-
Jun 17, 2026
Mar 20, 2024
2.3 LOW· v4
4.3 MEDIUM· v3
N/A· v2
The Chirp Access app contains a hard-coded password, BEACON_PASSWORD. An attacker within Bluetooth range could change configuration settings within the Bluetooth beacon, effectively disabling the application's ability to...Show more
The Chirp Access app contains a hard-coded password, BEACON_PASSWORD. An attacker within Bluetooth range could change configuration settings within the Bluetooth beacon, effectively disabling the application's ability to notify users when they are near a Beacon-enabled access point. This variable cannot be used to change the configuration settings of the door readers or locksets and does not affect the ability for authorized users of the mobile application to lock or unlock access points.Show less
1Unitronics
1Unilogic
Jun 17, 2026
Mar 18, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device's Firmware
1Ibm
1Storage Fusion Hci
Jun 17, 2026
Jan 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or enc...Show more
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 275671.Show less
1Preh
1Mib3 Firmware
Jun 17, 2026
Dec 1, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The console allows attackers with physical access to the MIB3 unit to gain full...Show more
The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The console allows attackers with physical access to the MIB3 unit to gain full control over the PWC chip. Vulnerability found on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.Show less
1Sonicwall
1Sonicos
Jun 17, 2026
Oct 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.