CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vsolcn 5V1600d Mini Firmware V1600d4l FirmwareV1600d Firmware+2 moreJun 17, 2026 Nov 29, 2020 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. An low-privileged (non-admin) attacker can use a hardcode...Show more |
1Cdatatec 2872408a Firmware 9008a Firmware9016a Firmware+25 moreJun 17, 2026 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S...Show more |
1Cdatatec 2872408a Firmware 9008a Firmware9016a Firmware+25 moreJun 17, 2026 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S...Show more |
1Cdatatec 2872408a Firmware 9008a Firmware9016a Firmware+25 moreJun 17, 2026 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S...Show more |
1Cdatatec 2872408a Firmware 9008a Firmware9016a Firmware+25 moreJun 17, 2026 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S...Show more |
1Barco 1Wepresent Wipg 1600w Firmware Jun 17, 2026 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password to access authenticated, administrative f...Show more |
1Barco 1Wepresent Wipg 1600w Firmware Jun 17, 2026 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W device has a hardcoded root password hash included...Show more |
1Redhat 1Advanced Cluster Management For Kubernetes Jun 17, 2026 Nov 23, 2020 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using t...Show more |
IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, o...Show more |
1Planet 2Nvr 1615 Firmware Nvr 915 FirmwareJun 17, 2026 Nov 18, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet. By exposing telnet on the Internet, remote root access on the device is possible. N...Show more |
1Airleader 1Airleader Master Control Jun 17, 2026 Nov 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service. |
2Fedoraproject Linuxfoundation2Fedora Nats ServerJun 17, 2026 Nov 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled. |
Studyplus App for Android v6.3.7 and earlier and Studyplus App for iOS v8.29.0 and earlier use a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtain...Show more |
1Imomobile 1Verve Connect Vh510 Firmware Jun 17, 2026 Nov 4, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credentials for the web management interface. A remote attacker could exploit this vulnerability to login and...Show more |
NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which it uses a hard-coded RC4 cipher key, which may lead to information disclosure. |
NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers with all BMC firmware versions, contains a vulnerability in the AMI BMC fi...Show more |
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which the firmware includes hard-co...Show more |
1Winstonprivacy 1Winston Firmware Jun 17, 2026 Oct 28, 2020 N/A· v4 7.1 HIGH· v3 5.6 MEDIUM· v2 Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials. |
1Microfocus 3Application Performance Management Operations BridgeOperations Bridge ManagerJun 17, 2026 Oct 27, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operati...Show more |
A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or decrypt server-side configuration files. |