← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qsan
3Sanos
Storage ManagerXevo
Jun 17, 2026
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate privileges. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
1Qsan
1Storage Manager
Jun 17, 2026
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
1Fortinet
1Fortiauthenticator
Jun 17, 2026
Jul 6, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sens...Show more
Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of the hard-coded key.Show less
1Arlo
1Q Plus Firmware
Jun 17, 2026
Jun 29, 2021
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus 1.9.0.3_278. Authentication is not required to exploit this vulnerability. The specific flaw exists...Show more
This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus 1.9.0.3_278. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSH service. The device can be booted into a special operation mode where hard-coded credentials are accepted for SSH authentication. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-12890.Show less
1Phoenixcontact
18Axl F Bk Eip Ef Firmware
Axl F Bk Eip FirmwareAxl F Bk Eth Firmware+15 more
Jun 17, 2026
Jun 25, 2021
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.
1Weidmueller
8Ie Wl Bl Ap Cl Eu Firmware
Ie Wl Bl Ap Cl Us FirmwareIe Wl Vl Ap Br Cl Eu Firmware+5 more
Jun 17, 2026
Jun 25, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities. The device operating system contains an undocumented encryption pa...Show more
In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts. An attacker can send diagnostic scripts while authenticated as a low privilege user to trigger this vulnerability.Show less
1Weidmueller
8Ie Wl Bl Ap Cl Eu Firmware
Ie Wl Bl Ap Cl Us FirmwareIe Wl Vl Ap Br Cl Eu Firmware+5 more
Jun 17, 2026
Jun 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the service agent binary allows for the decryption of captured traffic across the network from or to the devic...Show more
In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the service agent binary allows for the decryption of captured traffic across the network from or to the device.Show less
1Synology
1Calendar
Jun 17, 2026
Jun 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitive information via unspecified vectors.
1Ge
1Reason Rpv311 Firmware
Jun 17, 2026
Jun 16, 2021
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not required to exploit this vulnerability. The specific flaw exists within the...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware and filesystem of the device. The firmware and filesystem contain hard-coded default credentials. An attacker can leverage this vulnerability to execute code in the context of the download user. Was ZDI-CAN-11852.Show less
1Enphase
1Envoy Firmware
Jun 17, 2026
Jun 16, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts. The passwords for these accounts are hardcoded values derived from the...Show more
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts. The passwords for these accounts are hardcoded values derived from the MD5 hash of the username and serial number mixed with some static strings. The serial number can be retrieved by an unauthenticated user at /info.xml. These passwords can be easily calculated by an attacker; users are unable to change these passwords.Show less
1Zoll
1Defibrillator Dashboard
Jun 17, 2026
Jun 16, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information.
1Broadcom
1Brocade Sannav
Jun 17, 2026
Jun 9, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is not provided for PostgreSQL at install-time.
1Dlink
1Dir 885l Mfc Firmware
Jun 17, 2026
Jun 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to...Show more
The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.Show less
1Dlink
1Dir 880l Firmware
Jun 17, 2026
Jun 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive...Show more
The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.Show less
1Dlink
1Dir 868l Firmware
Jun 17, 2026
Jun 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive...Show more
The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.Show less
3Fedoraproject
RedhatTpm2 Tools Project
3Enterprise Linux
FedoraTpm2 Tools
Jun 17, 2026
Jun 4, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being...Show more
A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality.Show less
1Ceph
1Ceph Ansible
Jun 17, 2026
May 28, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force...Show more
A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.Show less
1Trendmicro
1Home Network Security
Jun 17, 2026
May 27, 2021
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could allow an attacker to use a specially crafted network request to lead to...Show more
Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could allow an attacker to use a specially crafted network request to lead to arbitrary authentication. An attacker must first obtain the ability to execute high-privileged code on the target device in order to exploit this vulnerability.Show less
1Ibm
1Security Guardium
Jun 17, 2026
May 24, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of inter...Show more
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313.Show less
1Ibm
1Security Identity Manager
Jun 17, 2026
May 20, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption...Show more
IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 200252.Show less