CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Jan 7, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jan 6, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administra...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jan 6, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administra...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jan 6, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administra...Show more |
2Citrix Supermicro5Netscaler Firmware Netscaler Sd Wan FirmwareNetscaler Sdx Firmware+2 moreNov 21, 2024 Jan 2, 2020 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private...Show more |
1Barco 3Clickshare Cs 100 Firmware Clickshare Cse 200 FirmwareClickshare Cse 800 FirmwareJun 17, 2026 Dec 16, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button firmware contains the private key of a test device-certificate. |
2Petwant Skymee2Petalk Ai Firmware Pf 103 FirmwareJun 17, 2026 Dec 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user. |
3Debian PuppetRedhat3Debian Linux Marionette CollectiveOpenshiftNov 21, 2024 Dec 13, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 mcollective has a default password set at install |
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password...Show more |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections. |
1Grandstream 13Gxv3500 Firmware Gxv3501 FirmwareGxv3504 Firmware+10 moreNov 21, 2024 Dec 11, 2019 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account "!#/" with th...Show more |
An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this accou...Show more |
An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could utilize this to gain root privileges on the system. |
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml. |
Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password. |
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key...Show more |
1Fortinet 2Forticlient FortiosJun 17, 2026 Nov 21, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and...Show more |
1Zyxel 9Gs1900 10hp Firmware Gs1900 16 FirmwareGs1900 24 Firmware+6 moreJun 17, 2026 Nov 14, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cryptographic key in sal_util_str_encrypt() in libsal.so.0.0. The paramete...Show more |
1Zyxel 9Gs1900 10hp Firmware Gs1900 16 FirmwareGs1900 24 Firmware+6 moreJun 17, 2026 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to authenticate users wishing to access a diagnostics or password-recover...Show more |
1Medtronic 3Valleylab Exchange Client Valleylab Ft10 Energy Platform FirmwareValleylab Fx8 Energy Platform FirmwareJun 17, 2026 Nov 8, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use mu...Show more |