← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Commscope
1Ruckus Vriot
Jun 17, 2026
Oct 26, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.
2Korenix
Pepperl Fuchs
26Es7506 Firmware
Es7510 Xt FirmwareEs7510 Firmware+23 more
Jun 17, 2026
Oct 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use...Show more
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.Show less
1Szuray
2Iptv/h.264 Video Encoder Firmware
Iptv/h.265 Video Encoder Firmware
Jun 17, 2026
Oct 6, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in the executable file.
3Jtechdigital
ProvideoinstrumentsSzuray
7H.264 Iptv Encoder 1080p@60hz Firmware
Iptv/h.264 Video Encoder FirmwareIptv/h.265 Video Encoder Firmware+4 more
Jun 17, 2026
Oct 6, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retr...Show more
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin password), and uploading a custom firmware update, to ultimately achieve arbitrary code execution.Show less
1Unisys
1Stealth
Jun 17, 2026
Oct 1, 2020
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal credentials.
1August
2August Home
Connect Wi Fi Bridge Firmware
Jun 17, 2026
Sep 30, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This is...Show more
Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This issue affects: August Connect Wi-Fi Bridge App version v10.11.0 and prior versions on Android. August Connect Firmware version 2.2.12 and prior versions.Show less
1Rubetek
3Rv 3406 Firmware
Rv 3409 FirmwareRv 3411 Firmware
Jun 17, 2026
Sep 25, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerabili...Show more
The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.Show less
1Ibm
1Data Risk Manager
Jun 17, 2026
Sep 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption...Show more
IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 184983.Show less
1Microfocus
1Operation Bridge Reporter
Jun 17, 2026
Sep 22, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user
1Microchip
76Atsama5d21c Cu Firmware
Atsama5d21c Cur FirmwareAtsama5d225c D1m Cur Firmware+73 more
Jun 17, 2026
Sep 14, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.
1Dlink
2Covr 2600r Firmware
Covr 3902 Firmware
Nov 21, 2024
Sep 14, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to gain privileged access to the router, and to extract sensitive data or m...Show more
D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to gain privileged access to the router, and to extract sensitive data or modify the configuration.Show less
1Hyland
1Onbase
Jun 17, 2026
Sep 11, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. PKI certificates have a private key that is the same across diff...Show more
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. PKI certificates have a private key that is the same across different customers' installations.Show less
1Ingenico
1Telium 2 Firmware
Nov 21, 2024
Sep 9, 2020
N/A· v4
6.6 MEDIUM· v3
7.2 HIGH· v2
Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
1Ingenico
1Telium 2 Firmware
Nov 21, 2024
Sep 9, 2020
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
1Pancakeapp
1Pancake
Jun 17, 2026
Sep 3, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which may lead to remote privilege escalation.
1Online Book Store Project
1Online Book Store
Jun 17, 2026
Aug 31, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.
1Ibm
2Guardium Data Encryption
Guardium For Cloud Key Management
Jun 17, 2026
Aug 26, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external component...Show more
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171832.Show less
1Cisco
5Csp 5228 W Firmware
Csp 5436 W FirmwareEncs 5406 W Firmware+2 more
Jun 17, 2026
Aug 26, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances could allow a...Show more
A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances could allow an unauthenticated, remote attacker to log into the NFVIS CLI of an affected device by using accounts that have a default, static password. The vulnerability exists because the affected software has user accounts with default, static passwords. An attacker with access to the NFVIS CLI of an affected device could exploit this vulnerability by logging into the CLI. A successful exploit could allow the attacker to access the NFVIS CLI with administrator privileges.Show less
1Secomea
1Gatemanager 8250 Firmware
Jun 17, 2026
Aug 25, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute commands as root.
1Verint
34320 Firmware
5620ptz FirmwareS5120fd Firmware
Jun 17, 2026
Aug 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD Verint_FW_0_42units. This could cause a confidentiality issue when using the FTP...Show more
A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD Verint_FW_0_42units. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols.Show less