CWE-259
204 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use of Hard-coded Password
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
CVEs (204)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Phoenixbroadband 1Poweragent Sc3 Bms Firmware May 13, 2026 Jun 2, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A Use of Hard-Coded Password issue was discovered in Phoenix Broadband PowerAgent SC3 BMS, all versions prior to v6.87. Use of a hard-coded password may allow unauthorized access to the device. |
Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password...Show more |
Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain access via a login request. |
1Sinapsitech 4Esolar Duo Photovoltaic System Monitor Esolar Light Photovoltaic System MonitorEsolar Photovoltaic System Monitor+1 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the at...Show more |