CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Philips 4Intellivue Mp Monitors Mp2/x2 Firmware Intellivue Mp Monitors Mp20 Mp90 FirmwareIntellivue Mp Monitors Mp5/5sc Firmware+1 moreJun 17, 2026 Sep 12, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN...Show more |
Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edition (APE) 3.8. |
2Auna Telestar12Bobs Rock Radio Firmware Connect 100 FirmwareDabman D10 Firmware+9 moreJun 17, 2026 Sep 11, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have a...Show more |
The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action. |
1Equeshome 1Elf Smart Plug Firmware Jun 17, 2026 Aug 29, 2019 N/A· v4 8.8 HIGH· v3 3.3 LOW· v2 The Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app. The communication happens over UDP port 27431. An attacker on the local ne...Show more |
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials. |
2Blackbox Onelan2Icompel Firmware Net Top Box FirmwareJun 17, 2026 Aug 26, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP. |
1Fortinet 1Fortirecorder Firmware Jun 17, 2026 Aug 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take cont...Show more |
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users. |
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the ....Show more |
1Cisco 3Integrated Management Controller Supervisor Ucs DirectorUcs Director Express For Big DataJun 17, 2026 Aug 21, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affec...Show more |
1Johnsoncontrols 1Metasys System Jun 17, 2026 Aug 20, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP). |
1Johnsoncontrols 1Metasys System Jun 17, 2026 Aug 20, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP). |
1Swann 1Swwhd Intcam Hd Firmware Nov 21, 2024 Aug 8, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31. |
1Elmelectronics 1Elm27 Firmware Jun 17, 2026 Jul 31, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle. |
Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an attacker to get access to the device via telnet. The telnet service is running on port 2323; it cannot be turned off and the credentials cannot be c...Show more |
1Audiocodes 4Median 500 Msbr Firmware Median 500l Msbr FirmwareMedian 800c Msbr Firmware+1 moreJun 17, 2026 Jul 20, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 all...Show more |
1Cisco 2Findit Network Manager Findit Network ProbeJun 17, 2026 Jul 17, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account th...Show more |
1Arlo 5Vmb3010 Firmware Vmb3500 FirmwareVmb4000 Firmware+2 moreJun 17, 2026 Jul 9, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to. |
Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation. |