← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
2Keycloak
Single Sign On
Jun 17, 2026
Jan 7, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client...Show more
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be 'service-account-test@placeholder.org'.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 6, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administra...Show more
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 6, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administra...Show more
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 6, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administra...Show more
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
2Citrix
Supermicro
5Netscaler Firmware
Netscaler Sd Wan FirmwareNetscaler Sdx Firmware+2 more
Nov 21, 2024
Jan 2, 2020
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private...Show more
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.Show less
1Barco
3Clickshare Cs 100 Firmware
Clickshare Cse 200 FirmwareClickshare Cse 800 Firmware
Jun 17, 2026
Dec 16, 2019
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button firmware contains the private key of a test device-certificate.
2Petwant
Skymee
2Petalk Ai Firmware
Pf 103 Firmware
Jun 17, 2026
Dec 13, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
3Debian
PuppetRedhat
3Debian Linux
Marionette CollectiveOpenshift
Nov 21, 2024
Dec 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
mcollective has a default password set at install
1Puppet
1Puppet Enterprise
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password...Show more
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise 2019.0.3 and 2018.1.9.Show less
1Amazon
1Blink Xt2 Sync Module Firmware
Jun 17, 2026
Dec 11, 2019
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections.
1Grandstream
13Gxv3500 Firmware
Gxv3501 FirmwareGxv3504 Firmware+10 more
Nov 21, 2024
Dec 11, 2019
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account "!#/" with th...Show more
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account "!#/" with the same password, which makes it easier for remote attackers to obtain access via a TELNET session.Show less
1Titanhq
1Webtitan
Jun 17, 2026
Dec 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this accou...Show more
An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.Show less
1Titanhq
1Webtitan
Jun 17, 2026
Dec 2, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could utilize this to gain root privileges on the system.
1Freeswitch
1Freeswitch
Jun 17, 2026
Dec 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
1Jalios
1Jcms
Jun 17, 2026
Nov 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password.
1Fortinet
1Fortios
Jun 17, 2026
Nov 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key...Show more
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).Show less
1Fortinet
2Forticlient
Fortios
Jun 17, 2026
Nov 21, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and...Show more
Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; URL rating in FortiClient) sent and received from Fortiguard severs by decrypting these messages. Affected products include FortiClient for Windows 6.0.6 and below, FortiOS 6.0.7 and below, FortiClient for Mac OS 6.2.1 and below.Show less
1Zyxel
9Gs1900 10hp Firmware
Gs1900 16 FirmwareGs1900 24 Firmware+6 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cryptographic key in sal_util_str_encrypt() in libsal.so.0.0. The paramete...Show more
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cryptographic key in sal_util_str_encrypt() in libsal.so.0.0. The parameters (salt, IV, and key data) are used to encrypt and decrypt all passwords using AES256 in CBC mode. With the parameters known, all previously encrypted passwords can be decrypted. This includes the passwords that are part of configuration backups or otherwise embedded as part of the firmware.Show less
1Zyxel
9Gs1900 10hp Firmware
Gs1900 16 FirmwareGs1900 24 Firmware+6 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to authenticate users wishing to access a diagnostics or password-recover...Show more
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to authenticate users wishing to access a diagnostics or password-recovery menu. Using the hardcoded cryptographic key found elsewhere in the firmware, these passwords can be decrypted. This is related to fds_sys_passDebugPasswd_ret() and fds_sys_passRecoveryPasswd_ret() in libfds.so.0.0.Show less
1Medtronic
3Valleylab Exchange Client
Valleylab Ft10 Energy Platform FirmwareValleylab Fx8 Energy Platform Firmware
Jun 17, 2026
Nov 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use mu...Show more
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use multiple sets of hard-coded credentials. If discovered, they can be used to read files on the device.Show less