CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fiberhome 1Hg6245d Firmware Jun 17, 2026 Feb 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / admin credentials for an ISP. |
1Fiberhome 1Hg6245d Firmware Jun 17, 2026 Feb 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / CUadmin credentials for an ISP. |
1Fiberhome 1Hg6245d Firmware Jun 17, 2026 Feb 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP. |
1Fiberhome 1Hg6245d Firmware Jun 17, 2026 Feb 10, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u credentials for an ISP. |
1Fiberhome 1Hg6245d Firmware Jun 17, 2026 Feb 10, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / user1234 credentials for an ISP. |
An issue was discovered on FiberHome HG6245D devices through RP2613. The web management is done over HTTPS, using a hardcoded private key that has 0777 permissions. |
1Fiberhome 1Hg6245d Firmware Jun 17, 2026 Feb 10, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered on FiberHome HG6245D devices through RP2613. Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g key. (The webs binary has de...Show more |
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users....Show more |
1Tk Star 1Q90 Junior Gps Horloge Firmware Jun 17, 2026 Feb 1, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup, a default password is used (123456) for administrative purposes. There is no prompt to change this...Show more |
1Mofinetwork 1Mofi4500 4gxelte Firmware Jun 17, 2026 Feb 1, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to accept an alternate hard-coded path to a public key that allows root access. This key is stored in...Show more |
1Mofinetwork 1Mofi4500 4gxelte Firmware Jun 17, 2026 Feb 1, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password is...Show more |
1Bosch 2Fsm 2500 Firmware Fsm 5000 FirmwareJun 17, 2026 Jan 26, 2021 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with admin-privileges. T...Show more |
An issue was discovered in Apexis Streaming Video Web Application on Geeni GNC-CW013 doorbell 1.8.1 devices. A remote attacker can take full control of the camera with a high-privileged account. The vulnerability exists...Show more |
1Mygeeni 1Gnc Cw013 Firmware Jun 17, 2026 Jan 26, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the Telnet service that allows a remote attacker to take full control of the device with a high-privileged account. The vulnera...Show more |
1Reolink 7Rlc 410 Firmware Rlc 422 FirmwareRlc 423 Firmware+4 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reolink P2P cameras outside of local network access |
1Cisco 1Smart Software Manager On Prem Jun 17, 2026 Jan 20, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static...Show more |
1Ibm 2Spectrum Lsf Spectrum Lsf SuiteJun 17, 2026 Jan 20, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitrary commands. IBM X-Force ID: 192586. |
1Sooil 3Anydana A Firmware Anydana I FirmwareDiabecare Rs FirmwareJun 17, 2026 Jan 19, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu of the insulin pump allows attackers with physical access to change insulin therapy settings. |
In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access...Show more |
1Siemens 8Scalance Xr324 12m Firmware Scalance Xr324 12m Ts FirmwareScalance Xr324 4m Eec Firmware+5 moreJun 17, 2026 Jan 12, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new uniqu...Show more |