CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Moxa 2Eds 510e Firmware Eds G516e FirmwareJun 17, 2026 Mar 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a hard-coded cryptographic key, increasing the possibility that confidential data can be recovered. |
1Moxa 55Pt 7528 12msc 12tx 4gsfp Hv Hv Firmware Pt 7528 12msc 12tx 4gsfp Hv FirmwarePt 7528 12msc 12tx 4gsfp Wv Wv Firmware+52 moreJun 17, 2026 Mar 24, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, these devices use a hard-coded service code for access to the console. |
1Moxa 55Pt 7528 12msc 12tx 4gsfp Hv Hv Firmware Pt 7528 12msc 12tx 4gsfp Hv FirmwarePt 7528 12msc 12tx 4gsfp Wv Wv Firmware+52 moreJun 17, 2026 Mar 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a hard-coded cryptographic key, which increases the possibility that confidential data c...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within...Show more |
An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have strong random keys, as demonstrated by use of the 8YSDaBtDHAB3EQkxPAyTz2I5DttzA9uR private key and t...Show more |
1Rockwellautomation 4Micrologix 1100 Firmware Micrologix 1400 A FirmwareMicrologix 1400 B Firmware+1 moreJun 17, 2026 Mar 16, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help...Show more |
1Ricoh 4Sp C250dn Firmware Sp C250sf FirmwareSp C252dn Firmware+1 moreJun 17, 2026 Mar 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow to an attacker to access and read information stored on the shared FTP f...Show more |
1Phoenixcontact 6Tc Cloud Client 1002 4g Firmware Tc Cloud Client 1002 Txtx FirmwareTc Router 2002t 3g Firmware+3 moreJun 17, 2026 Mar 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CL...Show more |
An exploitable firmware downgrade vulnerability exists in the firmware update package functionality of the WAGO e!COCKPIT automation software v1.6.1.5. A specially crafted firmware update file can allow an attacker to in...Show more |
A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recove...Show more |
1Ibm 1Security Information Queue Jun 17, 2026 Mar 2, 2020 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communicati...Show more |
A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 authentication and establ...Show more |
An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing...Show more |
The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13. |
1Cisco 1Smart Software Manager On Prem Jun 17, 2026 Feb 19, 2020 N/A· v4 9.1 CRITICAL· v3 8.8 HIGH· v2 A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-privileged account. The v...Show more |
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/. |
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system. |
1Xerox 12Colorqube 9201 Firmware Colorqube 9202 FirmwareColorqube 9203 Firmware+9 moreNov 21, 2024 Feb 13, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts. |
QNAP VioCard 300 has hardcoded RSA private keys. |
1Timetoolsltd 10Sc7105 Firmware Sc9205 FirmwareSc9705 Firmware+7 moreJun 17, 2026 Feb 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authenticati...Show more |