CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IZON IP 2.0.2: hard-coded password vulnerability |
1Polycom 1Hdx System Software Nov 21, 2024 Feb 10, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and...Show more |
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when...Show more |
1Eyesofnetwork 1Eyesofnetwork Jun 17, 2026 Feb 6, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attack...Show more |
1Ibm 1Security Identity Manager Jun 17, 2026 Feb 4, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption...Show more |
ZPanel 10.0.1 has insufficient entropy for its password reset process. |
Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server...Show more |
1Veraxsystems 1Network Management System Nov 21, 2024 Jan 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Verax NMS prior to 2.1.0 uses an encryption key that is hardcoded in a JAR archive. |
1Tp Link 4Tl Sc 3130 Firmware Tl Sc 3130g FirmwareTl Sc 3171g Firmware+1 moreNov 21, 2024 Jan 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicio...Show more |
1Zavio 2F3105 Firmware F312a FirmwareNov 21, 2024 Jan 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information. |
1Dlink 17Dcs 1100 Firmware Dcs 1100l FirmwareDcs 1130 Firmware+14 moreNov 21, 2024 Jan 28, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1....Show more |
The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account. |
Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account. |
The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY. |
1Gehealthcare 6Apexpro Telemetry Server Firmware Carescape Central Station Mai700 FirmwareCarescape Central Station Mas700 Firmware+3 moreJun 17, 2026 Jan 24, 2020 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products ut...Show more |
A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials. |
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary. |
1Mycarcontrols 1Mycar Controls Jun 17, 2026 Jan 15, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The MyCar Controls of AutoMobility Distribution Inc., mobile application contains hard-coded admin credentials. A remote unauthenticated attacker may be able to send commands to and retrieve data from a target MyCar unit...Show more |
1Abb 8Cp651 Web Firmware Cp651 FirmwareCp661 Web Firmware+5 moreJun 17, 2026 Jan 14, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. |
An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hardcoded credentials into a shell, gaining root execution privileges over...Show more |