← Back
CWE-259

204 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Use of Hard-coded Password

The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

JSON object

Loading...

CVEs (204)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phoenixbroadband
1Poweragent Sc3 Bms Firmware
May 13, 2026
Jun 2, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A Use of Hard-Coded Password issue was discovered in Phoenix Broadband PowerAgent SC3 BMS, all versions prior to v6.87. Use of a hard-coded password may allow unauthorized access to the device.
1Hospira
1Mednet
May 6, 2026
Apr 3, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password...Show more
Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.Show less
1Morpho
1Itemiser 3
May 6, 2026
Jul 26, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain access via a login request.
1Sinapsitech
4Esolar Duo Photovoltaic System Monitor
Esolar Light Photovoltaic System MonitorEsolar Photovoltaic System Monitor+1 more
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the at...Show more
These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.Show less