CWE-798
1,814 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,814)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Studyplus App for Android v6.3.7 and earlier and Studyplus App for iOS v8.29.0 and earlier use a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtain...Show more |
1Imomobile 1Verve Connect Vh510 Firmware Jun 17, 2026 Nov 4, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credentials for the web management interface. A remote attacker could exploit this vulnerability to login and...Show more |
NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which it uses a hard-coded RC4 cipher key, which may lead to information disclosure. |
NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers with all BMC firmware versions, contains a vulnerability in the AMI BMC fi...Show more |
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which the firmware includes hard-co...Show more |
1Winstonprivacy 1Winston Firmware Jun 17, 2026 Oct 28, 2020 N/A· v4 7.1 HIGH· v3 5.6 MEDIUM· v2 Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials. |
1Microfocus 3Application Performance Management Operations BridgeOperations Bridge ManagerJun 17, 2026 Oct 27, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operati...Show more |
A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or decrypt server-side configuration files. |
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header. |
2Korenix Pepperl Fuchs26Es7506 Firmware Es7510 Xt FirmwareEs7510 Firmware+23 moreJun 17, 2026 Oct 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use...Show more |
1Szuray 2Iptv/h.264 Video Encoder Firmware Iptv/h.265 Video Encoder FirmwareJun 17, 2026 Oct 6, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in the executable file. |
3Jtechdigital ProvideoinstrumentsSzuray7H.264 Iptv Encoder 1080p@60hz Firmware Iptv/h.264 Video Encoder FirmwareIptv/h.265 Video Encoder Firmware+4 moreJun 17, 2026 Oct 6, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retr...Show more |
Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal credentials. |
1August 2August Home Connect Wi Fi Bridge FirmwareJun 17, 2026 Sep 30, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This is...Show more |
1Rubetek 3Rv 3406 Firmware Rv 3409 FirmwareRv 3411 FirmwareJun 17, 2026 Sep 25, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerabili...Show more |
IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption...Show more |
1Microfocus 1Operation Bridge Reporter Jun 17, 2026 Sep 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user |
1Microchip 76Atsama5d21c Cu Firmware Atsama5d21c Cur FirmwareAtsama5d225c D1m Cur Firmware+73 moreJun 17, 2026 Sep 14, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets. |
1Dlink 2Covr 2600r Firmware Covr 3902 FirmwareNov 21, 2024 Sep 14, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to gain privileged access to the router, and to extract sensitive data or m...Show more |
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. PKI certificates have a private key that is the same across diff...Show more |