CWE-259
204 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use of Hard-coded Password
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
CVEs (204)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netapp 1Ontap Select Deploy Administration Utility Jun 17, 2026 Apr 17, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentia...Show more |
1Mitel 146905 Firmware 6910 Firmware6915 Firmware+11 moreJun 17, 2026 Apr 8, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password). |
Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by def...Show more |
1Nec 59Aterm Cr2500p Firmware Aterm Mr01ln FirmwareAterm Mr02ln Firmware+56 moreJun 17, 2026 Mar 28, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Use of Hard-coded Password in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF...Show more |
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability |
The Chirp Access app contains a hard-coded password, BEACON_PASSWORD. An attacker within Bluetooth range could change configuration settings within the Bluetooth beacon, effectively disabling the application's ability to...Show more |
Unitronics Unistream Unilogic – Versions prior to 1.35.227 -
CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device's Firmware
|
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or enc...Show more |
The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The console allows attackers with physical access to the MIB3 unit to gain full...Show more |
SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function. |
1Viessmann 1Vitogate 300 Firmware Jun 17, 2026 Sep 27, 2023 N/A· v4 9.8 CRITICAL· v3 5.8 MEDIUM· v2 A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of the component Web Management Interface. T...Show more |
1Juplink 1Rx4 1500 Firmware Jun 17, 2026 Sep 18, 2023 N/A· v4 9.8 CRITICAL· v3 5.8 MEDIUM· v2 Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user. |
Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoo...Show more |
1Motorola 1Mbts Site Controller Firmware Jun 17, 2026 Aug 29, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-cod...Show more |
A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input admin leads to use of hard-coded password....Show more |
1Mitsubishielectric 4Fx5 Enet/ip Firmware Rj71eip91 FirmwareSw1dnn Eipct Bd Firmware+1 moreJun 17, 2026 Jun 2, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenti...Show more |
This vulnerability enables ssh access to minikube container using a default password. |
A vulnerability, which was classified as problematic, has been found in cnoa OA up to 5.1.1.5. Affected by this issue is some unknown functionality of the file /index.php?app=main&func=passport&action=login. The manipula...Show more |
A vulnerability, which was classified as critical, was found in USR USR-G806 1.0.41. Affected is an unknown function of the component Web Management Page. The manipulation of the argument username/password with the input...Show more |
1Siemens 26gk1411 1ac00 Firmware 6gk1411 5ac00 FirmwareJun 17, 2026 May 9, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC712 (All versions < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1), SIMATI...Show more |