CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple Wireless M-Bus devices by Enbra use Hard-coded Credentials in Security mode 5 without an option to change the encryption key. An adversary can learn all information that is available in Enbra EWM. |
1Qnap 2Qsw M2116p 2t2s Firmware QunetswitchJun 17, 2026 Sep 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sens...Show more |
1Bab Technologie 1Eibport Firmware Jun 17, 2026 Sep 9, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 BAB TECHNOLOGIE GmbH eibPort V3. Each device has its own unique hard coded and weak root SSH key passphrase known as 'eibPort string'. This is usable and the final part of an attack chain to gain SSH root access. |
1Onyaktech Comments Pro Project 1Onyaktech Comments Pro Jun 17, 2026 Sep 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the installer, decompile it, and discover a hardcoded IV used to encrypt the username and userid in the co...Show more |
A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system. |
Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors. |
1Pepperl Fuchs 2Wha Gw F2d2 0 As Z2 Eth.eip Firmware Wha Gw F2d2 0 As Z2 Eth FirmwareJun 17, 2026 Aug 31, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials. |
1Ibm 2Sterling External Authentication Server Sterling Secure ProxyJun 17, 2026 Aug 30, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external...Show more |
D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If an attacker succeeds in recovering the cleartext password of the identified hash value, he will be...Show more |
1Dlink 1Dvx 2000ms Firmware Jun 17, 2026 Aug 23, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values. |
1Dlink 1Dvg 3104ms Firmware Jun 17, 2026 Aug 23, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be re...Show more |
1Altus 15Hadron Xtorm Hx3040 Firmware Nexto Nx3003 FirmwareNexto Nx3004 Firmware+12 moreJun 17, 2026 Aug 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto...Show more |
A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and 5.0.x may allow a remote and unauthenticated attacker to execute unaut...Show more |
In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the attacker can inject malicious OS commands...Show more |
SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in ServerConf.config file in the client. |
In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the attacker can inject malicious OS commands...Show more |
1Qnap 5Viocard 100 Firmware Viocard 30 FirmwareViocard 300 Firmware+2 moreNov 21, 2024 Aug 9, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authorization mechanism is no...Show more |
1Ecobee 1Ecobee3 Lite Firmware Jun 17, 2026 Aug 3, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected bootloader environment through the serial console. |
Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: All versions prior to 1.7.5,The application encrypts on the application layer of the communication p...Show more |
1Swisslog Healthcare 1Hmi 3 Control Panel Firmware Jun 17, 2026 Aug 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released versions of software before Nexus Software 7.2.5.7. The device has two user accounts with passwords tha...Show more |