CWE-259
194 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use of Hard-coded Password
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
CVEs (194)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Inhandnetworks 1Ir302 Firmware Jun 17, 2026 May 12, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can se...Show more |
1Bender 2Cc612 Firmware Icc15xx FirmwareJun 17, 2026 Apr 27, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the passwor...Show more |
Dell EMC CloudLink 7.1 and all prior versions contain a Hard-coded Password Vulnerability. A remote high privileged attacker, with the knowledge of the hard-coded credentials, may potentially exploit this vulnerability t...Show more |
A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords |
1Qnap 2Qsw M2116p 2t2s Firmware QunetswitchJun 17, 2026 Sep 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sens...Show more |
1Dell 1Emc Data Protection Advisor Jun 17, 2026 Jul 28, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that is protected with a hard-coded password. A remote unauthenticated malicious user with the knowledge...Show more |
1Schneider Electric 6Evlink City Evc1s22p4 Firmware Evlink City Evc1s7p4 FirmwareEvlink Parking Ev.2 Firmware+3 moreJun 17, 2026 Jul 21, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart...Show more |
A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of...Show more |
The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to ex...Show more |
1Qsan 3Sanos Storage ManagerXevoJun 17, 2026 Jul 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate privileges. Suggest contacting with QSAN and refer to recommendations in QSAN Document. |
1Xerox 10Altalink B8045 Firmware Altalink B8055 FirmwareAltalink B8065 Firmware+7 moreJun 17, 2026 Apr 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded passwords which can be exploited and allow u...Show more |
The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these hard-coded credentials on the MU320E (all firmware versions prior to v04A00.1). |
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1). |
1Netgear 43Br200 Firmware Br500 FirmwareD7800 Firmware+40 moreJun 17, 2026 Mar 5, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the...Show more |
A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QE...Show more |
1Siemens 1Dca Vantage Analyzer Firmware Jun 17, 2026 Oct 13, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Affected d...Show more |
1Baxter 1Sigma Spectrum Infusion System Firmware Jun 17, 2026 Jun 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FTP service with hard-coded credentials. |
1Baxter 1Sigma Spectrum Infusion System Firmware Jun 17, 2026 Jun 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a Telnet service on Port 1023 with hard-coded credentials. |
1Baxter 1Sigma Spectrum Infusion System Firmware Jun 17, 2026 Jun 29, 2020 N/A· v4 2.4 LOW· v3 2.1 LOW· v2 Baxter Sigma Spectrum Infusion Pumps Sigma Spectrum Infusion System v's6.x model 35700BAX & Baxter Spectrum Infusion System v's8.x model 35700BAX2 contain hardcoded passwords when physically entered on the keypad provide...Show more |
1Baxter 2Prismaflex Firmware Prismax FirmwareJun 17, 2026 Jun 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Managemen...Show more |