CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges. |
1Technicolor 2C2000t Firmware C2100t FirmwareNov 21, 2024 Nov 6, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Technicolor C2000T and C2100T uses hard-coded cryptographic keys. |
The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user account in an "unattend.xml" file left ov...Show more |
1Ibm 1Security Guardium Big Data Intelligence Jun 17, 2026 Oct 29, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to obtain highly sensitive information. IBM X-Force ID: 161035. |
2Inea Mitsubishielectric2Me Rtu Firmware Smartrtu FirmwareJun 17, 2026 Oct 28, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint could allow an...Show more |
2Inea Mitsubishielectric2Me Rtu Firmware Smartrtu FirmwareJun 17, 2026 Oct 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthorised access or disclose encrypted data on...Show more |
Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is configured using hard-coded credentials. These credentials could allow...Show more |
1Milesight 1Ip Security Camera Firmware Nov 21, 2024 Oct 25, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations. |
1Milesight 1Ip Security Camera Firmware Nov 21, 2024 Oct 25, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are accessible if the customer has not configured 10 actual user accounts. |
1Milesight 1Ip Security Camera Firmware Nov 21, 2024 Oct 25, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory. |
1Broadcom 2Ca Performance Management Network OperationsJun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security. |
1Cobham 1Explorer 710 Firmware Jun 17, 2026 Oct 10, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from available versions to gain authenticated...Show more |
The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker to authenticate to the service using hard...Show more |
In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthorized users gaining access to the system. |
1Broadcom 1Network Flow Analysis Jun 17, 2026 Oct 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security. |
2Sandisk Westerndigital2Ssd Dashboard Ssd DashboardJun 17, 2026 Sep 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded password. An application update that addr...Show more |
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may allow an attacker to access configuration...Show more |
1Westerndigital 1Wd My Book Firmware Jun 17, 2026 Sep 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_a...Show more |
1Telestar 11Bobs Rock Radio Firmware Dabman D10 FirmwareDabman I30 Stereo Firmware+8 moreJun 17, 2026 Sep 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have i...Show more |
1Ifw8 5Fr5 E Firmware Fr5 FirmwareFr6 S Firmware+2 moreJun 17, 2026 Sep 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code. |