CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header. |
2Korenix Pepperl Fuchs26Es7506 Firmware Es7510 Xt FirmwareEs7510 Firmware+23 moreJun 17, 2026 Oct 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use...Show more |
1Szuray 2Iptv/h.264 Video Encoder Firmware Iptv/h.265 Video Encoder FirmwareJun 17, 2026 Oct 6, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in the executable file. |
3Jtechdigital ProvideoinstrumentsSzuray7H.264 Iptv Encoder 1080p@60hz Firmware Iptv/h.264 Video Encoder FirmwareIptv/h.265 Video Encoder Firmware+4 moreJun 17, 2026 Oct 6, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retr...Show more |
Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal credentials. |
1August 2August Home Connect Wi Fi Bridge FirmwareJun 17, 2026 Sep 30, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This is...Show more |
1Rubetek 3Rv 3406 Firmware Rv 3409 FirmwareRv 3411 FirmwareJun 17, 2026 Sep 25, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerabili...Show more |
IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption...Show more |
1Microfocus 1Operation Bridge Reporter Jun 17, 2026 Sep 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user |
1Microchip 76Atsama5d21c Cu Firmware Atsama5d21c Cur FirmwareAtsama5d225c D1m Cur Firmware+73 moreJun 17, 2026 Sep 14, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets. |
1Dlink 2Covr 2600r Firmware Covr 3902 FirmwareNov 21, 2024 Sep 14, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to gain privileged access to the router, and to extract sensitive data or m...Show more |
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. PKI certificates have a private key that is the same across diff...Show more |
Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N. |
Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N. |
Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which may lead to remote privilege escalation. |
1Online Book Store Project 1Online Book Store Jun 17, 2026 Aug 31, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access. |
1Ibm 2Guardium Data Encryption Guardium For Cloud Key ManagementJun 17, 2026 Aug 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external component...Show more |
1Cisco 5Csp 5228 W Firmware Csp 5436 W FirmwareEncs 5406 W Firmware+2 moreJun 17, 2026 Aug 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances could allow a...Show more |
1Secomea 1Gatemanager 8250 Firmware Jun 17, 2026 Aug 25, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute commands as root. |
1Verint 34320 Firmware 5620ptz FirmwareS5120fd FirmwareJun 17, 2026 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD Verint_FW_0_42units. This could cause a confidentiality issue when using the FTP...Show more |