CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Jun 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI bac...Show more |
1Schneider Electric 1Vijeo Designer Jun 17, 2026 Jun 16, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write when downloading and...Show more |
1Schneider Electric 2Os Loader Unity LoaderJun 17, 2026 Jun 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are used to simplify file transfer. Today the use of fixed credentials is con...Show more |
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, o...Show more |
1Usavisionsys 5Geovision Gv As1010 Firmware Geovision Gv As210 FirmwareGeovision Gv As410 Firmware+2 moreJun 17, 2026 Jun 12, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GeoVision Door Access Control device family is hardcoded with a root password, which adopting an identical password in all devices. |
1Sap 2Commerce Commerce Data HubJun 17, 2026 Jun 9, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authentication and/or authorization that has been configured by the system a...Show more |
1Foxitsoftware 2Phantompdf ReaderJun 17, 2026 Jun 4, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows information disclosure of a hardcoded username and password in the DocuSign plugin. |
Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configur...Show more |
A vulnerability in the virtual console authentication of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allo...Show more |
IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or enc...Show more |
IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of inter...Show more |
An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software. |
1Mylittletools 1Mylittleadmin Jun 17, 2026 May 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP...Show more |
1Netgear 3Rbs50y Firmware Srr60 FirmwareSrs60 FirmwareJun 17, 2026 May 18, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The root...Show more |
GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means anyone can decrypt sensitive data stored using this key. It is possible...Show more |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and execute arbitrary code on...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 May 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 May 6, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account...Show more |
1Tp Link 7Nc200 Firmware Nc210 FirmwareNc220 Firmware+4 moreJun 17, 2026 May 4, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200...Show more |
Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key. |