← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Izoncam
1Izon Ip Firmware
Nov 21, 2024
Feb 12, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
IZON IP 2.0.2: hard-coded password vulnerability
1Polycom
1Hdx System Software
Nov 21, 2024
Feb 10, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and...Show more
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password.Show less
1Mediawiki
1Mediawiki
Nov 21, 2024
Feb 8, 2020
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when...Show more
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.Show less
1Eyesofnetwork
1Eyesofnetwork
Jun 17, 2026
Feb 6, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attack...Show more
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token.Show less
1Ibm
1Security Identity Manager
Jun 17, 2026
Feb 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption...Show more
IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511.Show less
1Zpanelcp
1Zpanel
Nov 21, 2024
Feb 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ZPanel 10.0.1 has insufficient entropy for its password reset process.
1Apereo
1Opencast
Jun 17, 2026
Jan 30, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server...Show more
Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server can get access to all servers which allow log-in using the same credentials without ever needing the credentials. This problem is fixed in Opencast 7.6 and Opencast 8.1Show less
1Veraxsystems
1Network Management System
Nov 21, 2024
Jan 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Verax NMS prior to 2.1.0 uses an encryption key that is hardcoded in a JAR archive.
1Tp Link
4Tl Sc 3130 Firmware
Tl Sc 3130g FirmwareTl Sc 3171g Firmware+1 more
Nov 21, 2024
Jan 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicio...Show more
A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized access to CGI files.Show less
1Zavio
2F3105 Firmware
F312a Firmware
Nov 21, 2024
Jan 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information.
1Dlink
17Dcs 1100 Firmware
Dcs 1100l FirmwareDcs 1130 Firmware+14 more
Nov 21, 2024
Jan 28, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1....Show more
An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU, DCS-2102 1.06_FR, DCS-2102 1.06, DCS-2102 1.05_RU, DCS-1130L 1.04, DCS-1130 1.04_US, DCS-1130 1.03, DCS-1100L 1.04, DCS-1100 1.04_US, and DCS-1100 1.03 due to hard-coded credentials that serve as a backdoor, which allows remote attackers to access the RTSP video stream.Show less
1Intelliantech
1Aptus
Jun 17, 2026
Jan 27, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account.
1Intelliantech
1Aptus Web
Jun 17, 2026
Jan 27, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.
1Intelliantech
1Aptus
Jun 17, 2026
Jan 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.
1Gehealthcare
6Apexpro Telemetry Server Firmware
Carescape Central Station Mai700 FirmwareCarescape Central Station Mas700 Firmware+3 more
Jun 17, 2026
Jan 24, 2020
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products ut...Show more
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.Show less
1Fortinet
1Fortisiem
Jun 17, 2026
Jan 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.
1Taskautomation
1Carbonftp
Jun 17, 2026
Jan 21, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary.
1Mycarcontrols
1Mycar Controls
Jun 17, 2026
Jan 15, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The MyCar Controls of AutoMobility Distribution Inc., mobile application contains hard-coded admin credentials. A remote unauthenticated attacker may be able to send commands to and retrieve data from a target MyCar unit...Show more
The MyCar Controls of AutoMobility Distribution Inc., mobile application contains hard-coded admin credentials. A remote unauthenticated attacker may be able to send commands to and retrieve data from a target MyCar unit. This may allow the attacker to learn the location of a target, or gain unauthorized physical access to a vehicle. This issue affects AutoMobility MyCar versions prior to 3.4.24 on iOS and versions prior to 4.1.2 on Android. This issue has additionally been fixed in Carlink, Link, Visions MyCar, and MyCar Kia.Show less
1Abb
8Cp651 Web Firmware
Cp651 FirmwareCp661 Web Firmware+5 more
Jun 17, 2026
Jan 14, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the HMI interface.
1Billion
1Sg600 R2 Firmware
Jun 17, 2026
Jan 9, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hardcoded credentials into a shell, gaining root execution privileges over...Show more
An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hardcoded credentials into a shell, gaining root execution privileges over the device.Show less