← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fortinet
1Fortios
Jun 17, 2026
Dec 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering.
1Kaseya
1Unitrends Backup
Jun 17, 2026
Dec 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.
1Govicture
1Wr1200 Firmware
Jun 17, 2026
Nov 30, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of...Show more
An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web interface).Show less
1Govicture
1Wr1200 Firmware
Jun 17, 2026
Nov 30, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device default Wi-Fi password corresponds to th...Show more
An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device default Wi-Fi password corresponds to the last 4 bytes of the MAC address of its 2.4 GHz network interface controller (NIC). An attacker within scanning range of the Wi-Fi network can thus scan for Wi-Fi networks to obtain the default key.Show less
1Hej
1Hejhome Gkw Ic052 Firmware
Jun 17, 2026
Nov 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, factory reset, snapshot etc..)
1Airangel
5Hsmx App 1000 Firmware
Hsmx App 100 FirmwareHsmx App 20000 Firmware+2 more
Jun 17, 2026
Nov 10, 2021
N/A· v4
10.0 CRITICAL· v3
6.4 MEDIUM· v2
Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials.
1Formalms
1Formalms
Jun 17, 2026
Nov 10, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
1Knx
1Engineering Tool Software 6
Jun 17, 2026
Nov 9, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information, a similar issue to CVE-2021-36799. NOTE: The vendor disputes this be...Show more
KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information, a similar issue to CVE-2021-36799. NOTE: The vendor disputes this because it is not the responsibility of the ETS to securely store cryptographic key material when it is not being exportedShow less
1Cisco
1Policy Suite
Jun 17, 2026
Nov 4, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-us...Show more
A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-use of static SSH keys across installations. An attacker could exploit this vulnerability by extracting a key from a system under their control. A successful exploit could allow the attacker to log in to an affected system as the root user.Show less
1Auvesy
1Versiondog
Jun 17, 2026
Oct 22, 2021
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries.
1Iongroup
1Wallstreet Suite
Jun 17, 2026
Oct 15, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than the average authenticated user. NOTE: the vendor disputes this because the password is not hardcoded (...Show more
A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than the average authenticated user. NOTE: the vendor disputes this because the password is not hardcoded (it can be changed during installation or at any later time).Show less
1Moxa
1Mxview
Jun 17, 2026
Oct 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords
1Cisco
16Business 220 16p 2g Firmware
Business 220 16t 2g FirmwareBusiness 220 24fp 4g Firmware+13 more
Jun 17, 2026
Oct 6, 2021
N/A· v4
5.5 MEDIUM· v3
3.6 LOW· v2
Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account....Show more
Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
16Business 220 16p 2g Firmware
Business 220 16t 2g FirmwareBusiness 220 24fp 4g Firmware+13 more
Jun 17, 2026
Oct 6, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account....Show more
Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Reiner Sct
1Timecard
Jun 17, 2026
Sep 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.
1Ecoa
3Ecs Router Controller Ecs Firmware
Riskbuster FirmwareRiskterminator
Jun 17, 2026
Sep 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s privilege without logging in.
1Zohocorp
1Manageengine Remote Access Plus
Jun 17, 2026
Sep 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.
1Zohocorp
1Manageengine Remote Access Plus
Jun 17, 2026
Sep 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive.
1Ibm
1Security Guardium
Jun 17, 2026
Sep 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of inter...Show more
IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 186697.Show less
1Dlink
1Dir 3040 Firmware
Jun 17, 2026
Sep 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request can lead to command execution. An attacker can connect to the MQTT servi...Show more
An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request can lead to command execution. An attacker can connect to the MQTT service to trigger this vulnerability.Show less