CWE-798
1,814 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,814)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing...Show more |
The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13. |
1Cisco 1Smart Software Manager On Prem Jun 17, 2026 Feb 19, 2020 N/A· v4 9.1 CRITICAL· v3 8.8 HIGH· v2 A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-privileged account. The v...Show more |
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/. |
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system. |
1Xerox 12Colorqube 9201 Firmware Colorqube 9202 FirmwareColorqube 9203 Firmware+9 moreNov 21, 2024 Feb 13, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts. |
QNAP VioCard 300 has hardcoded RSA private keys. |
1Timetoolsltd 10Sc7105 Firmware Sc9205 FirmwareSc9705 Firmware+7 moreJun 17, 2026 Feb 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authenticati...Show more |
IZON IP 2.0.2: hard-coded password vulnerability |
1Polycom 1Hdx System Software Nov 21, 2024 Feb 10, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and...Show more |
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when...Show more |
1Eyesofnetwork 1Eyesofnetwork Jun 17, 2026 Feb 6, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attack...Show more |
1Ibm 1Security Identity Manager Jun 17, 2026 Feb 4, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption...Show more |
ZPanel 10.0.1 has insufficient entropy for its password reset process. |
Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server...Show more |
1Veraxsystems 1Network Management System Nov 21, 2024 Jan 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Verax NMS prior to 2.1.0 uses an encryption key that is hardcoded in a JAR archive. |
1Tp Link 4Tl Sc 3130 Firmware Tl Sc 3130g FirmwareTl Sc 3171g Firmware+1 moreNov 21, 2024 Jan 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicio...Show more |
1Zavio 2F3105 Firmware F312a FirmwareNov 21, 2024 Jan 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information. |
1Dlink 17Dcs 1100 Firmware Dcs 1100l FirmwareDcs 1130 Firmware+14 moreNov 21, 2024 Jan 28, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1....Show more |
The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account. |