← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Mar 6, 2026
6.9 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
1Rustdesk
2Rustdesk
Rustdesk Server
Jul 19, 2026
Mar 5, 2026
6.9 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat...Show more
Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Sniffing Attacks. The client places the preset address-book password verbatim into the heartbeat sync JSON body (src/hbbs_http/sync.rs). Over an intact HTTPS session it is not exposed in transit, but it is a reusable shared secret rather than a zero-knowledge proof, so it is recovered by any party that becomes the API endpoint - under the re-homed/rogue API server (CVE-2026-30797) - and the leaked credential then authorizes the server-side address book. This vulnerability is associated with program files src/hbbs_http/sync.rs and program routines heartbeat sync body builder (emits preset-address-book-password). This issue affects RustDesk Client: through 1.4.8.Show less
1Datacast
1Sfx2100 Firmware
Jun 17, 2026
Mar 5, 2026
8.6 HIGH· v4
10.0 CRITICAL· v3
N/A· v2
IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world-readable. The configuration files (e.g.,...Show more
IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world-readable. The configuration files (e.g., zebra.conf, bgpd.conf, ospfd.conf, ripd.conf) contain hardcoded or otherwise insecure plaintext passwords (including “enable”/privileged-mode credentials). A remote actor is able to abuse the reuse/hardcoded nature of these credentials to further access other systems in the network, gain a foothold on the satellite receiver or potentially locally privilege escalate.Show less
1Extremenetworks
1Extremecloud Iq Site Engine
Jun 17, 2026
Mar 2, 2026
6.0 MEDIUM· v4
4.9 MEDIUM· v3
N/A· v2
In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive parameters from HTTP responses. Althoug...Show more
In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive parameters from HTTP responses. Although credentials appear redacted in the user interface, the application returns the underlying credential values in the HTTP response, enabling an authorized administrator to recover stored secrets that may exceed their intended access. We would like to thank the Lockheed Martin Red Team for responsibly reporting this issue and working with us through coordinated disclosure.Show less
5Google
LinuxfoundationOpenwrt+2 more
5Android
OpenwrtRdk B+2 more
Jun 17, 2026
Mar 2, 2026
N/A· v4
4.6 MEDIUM· v3
N/A· v2
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution pr...Show more
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10607099; Issue ID: MSV-6118.Show less
1Gradio Project
1Gradio
Jun 17, 2026
Feb 27, 2026
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAut...Show more
Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth components (e.g. `gr.LoginButton`) are used. When a user visits `/login/huggingface`, the server retrieves its own Hugging Face access token via `huggingface_hub.get_token()` and stores it in the visitor's session cookie. If the application is network-accessible, any remote attacker can trigger this flow to steal the server owner's HF token. The session cookie is signed with a hardcoded secret derived from the string `"-v4"`, making the payload trivially decodable. Version 6.6.0 fixes the issue.Show less
1Johnsoncontrols
1Frick Controls Quantum Hd Firmware
Aug 24, 2026
Feb 27, 2026
6.9 MEDIUM· v4
9.8 CRITICAL· v3
N/A· v2
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitiv...Show more
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise This issue affects Frick Controls Quantum HD version 10.22 and prior.Show less
1Ev.energy
1Ev.energy
Jun 17, 2026
Feb 27, 2026
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
1Mobility46
1Mobility46.se
Jun 17, 2026
Feb 27, 2026
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
1Swtchenergy
1Swtchenergy.com
Jun 17, 2026
Feb 27, 2026
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
1Ev2go
1Ev2go.io
Jun 17, 2026
Feb 27, 2026
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
1Chargemap
1Chargemap.com
Jun 17, 2026
Feb 27, 2026
6.9 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
1Cloudcharge
1Cloudcharge.se
Jun 17, 2026
Feb 27, 2026
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
-
-
Jun 17, 2026
Feb 25, 2026
N/A· v4
3.8 LOW· v3
N/A· v2
A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users.
-
-
Jun 17, 2026
Feb 20, 2026
N/A· v4
5.7 MEDIUM· v3
N/A· v2
The web management interface of the device renders the passwords in a plaintext input field. The current password is directly visible to anyone with access to the UI, potentially exposing administrator credentials to...Show more
The web management interface of the device renders the passwords in a plaintext input field. The current password is directly visible to anyone with access to the UI, potentially exposing administrator credentials to unauthorized observation via shoulder surfing, screenshots, or browser form caching.Show less
1Openclaw
1Openclaw
Jun 17, 2026
Feb 20, 2026
6.9 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, when request URLs include `https://api.telegram.org/bot<token>/...`). Prior to version 2026.2.15, OpenC...Show more
OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, when request URLs include `https://api.telegram.org/bot<token>/...`). Prior to version 2026.2.15, OpenClaw logged these strings without redaction, which could leak the bot token into logs, crash reports, CI output, or support bundles. Disclosure of a Telegram bot token allows an attacker to impersonate the bot and take over Bot API access. Users should upgrade to version 2026.2.15 to obtain a fix and rotate the Telegram bot token if it may have been exposed.Show less
1N8n
1N8n
Jun 17, 2026
Feb 6, 2026
5.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send requests with credentials t...Show more
n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send requests with credentials to unintended domains, potentially leading to credential exfiltration. This only might affect user who have credentials that use wildcard domain patterns (e.g., *.example.com) in the "Allowed domains" setting. This issue is fixed in version 1.121.0 and later.Show less
1Moxa
35Uc 1222a Firmware
Uc 2222a T Ap FirmwareUc 2222a T Eu Firmware+32 more
Jun 17, 2026
Feb 5, 2026
7.0 HIGH· v4
6.8 MEDIUM· v3
N/A· v2
Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access...Show more
Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface.  Access to the bootloader menu does not allow full system takeover or privilege escalation. The bootloader enforces digital signature verification and only permits flashing of Moxa-signed images. As a result, an attacker cannot install malicious firmware or execute arbitrary code. The primary impact is limited to a potential temporary denial-of-service condition if a valid image is reflashed. Remote exploitation is not possible.Show less
-
-
Jun 17, 2026
Feb 5, 2026
2.4 LOW· v4
N/A· v3
N/A· v2
YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unaut...Show more
YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.Show less
1Edimax
1Ew 7438rpn Mini Firmware
Jun 17, 2026
Feb 3, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive informatio...Show more
Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables.Show less