← Back
CWE-798

1,814 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,814)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moxa
1Awk 3131a Firmware
Jun 17, 2026
Feb 25, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing...Show more
An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.Show less
1Moxa
1Awk 3131a Firmware
Jun 17, 2026
Feb 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.
1Cisco
1Smart Software Manager On Prem
Jun 17, 2026
Feb 19, 2020
N/A· v4
9.1 CRITICAL· v3
8.8 HIGH· v2
A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-privileged account. The v...Show more
A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-privileged account. The vulnerability is due to a system account that has a default and static password and is not under the control of the system administrator. An attacker could exploit this vulnerability by using this default account to connect to the affected system. A successful exploit could allow the attacker to obtain read and write access to system data, including the configuration of an affected device. The attacker would gain access to a sensitive portion of the system, but the attacker would not have full administrative rights to control the device.Show less
1Netsweeper
1Netsweeper
Nov 21, 2024
Feb 19, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.
1Hcltech
1Appscan
Jun 17, 2026
Feb 14, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.
1Xerox
12Colorqube 9201 Firmware
Colorqube 9202 FirmwareColorqube 9203 Firmware+9 more
Nov 21, 2024
Feb 13, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.
1Qnap
1Viocard 300 Firmware
Nov 21, 2024
Feb 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
QNAP VioCard 300 has hardcoded RSA private keys.
1Timetoolsltd
10Sc7105 Firmware
Sc9205 FirmwareSc9705 Firmware+7 more
Jun 17, 2026
Feb 13, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authenticati...Show more
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."Show less
1Izoncam
1Izon Ip Firmware
Nov 21, 2024
Feb 12, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
IZON IP 2.0.2: hard-coded password vulnerability
1Polycom
1Hdx System Software
Nov 21, 2024
Feb 10, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and...Show more
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password.Show less
1Mediawiki
1Mediawiki
Nov 21, 2024
Feb 8, 2020
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when...Show more
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.Show less
1Eyesofnetwork
1Eyesofnetwork
Jun 17, 2026
Feb 6, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attack...Show more
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token.Show less
1Ibm
1Security Identity Manager
Jun 17, 2026
Feb 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption...Show more
IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511.Show less
1Zpanelcp
1Zpanel
Nov 21, 2024
Feb 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ZPanel 10.0.1 has insufficient entropy for its password reset process.
1Apereo
1Opencast
Jun 17, 2026
Jan 30, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server...Show more
Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server can get access to all servers which allow log-in using the same credentials without ever needing the credentials. This problem is fixed in Opencast 7.6 and Opencast 8.1Show less
1Veraxsystems
1Network Management System
Nov 21, 2024
Jan 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Verax NMS prior to 2.1.0 uses an encryption key that is hardcoded in a JAR archive.
1Tp Link
4Tl Sc 3130 Firmware
Tl Sc 3130g FirmwareTl Sc 3171g Firmware+1 more
Nov 21, 2024
Jan 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicio...Show more
A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized access to CGI files.Show less
1Zavio
2F3105 Firmware
F312a Firmware
Nov 21, 2024
Jan 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information.
1Dlink
17Dcs 1100 Firmware
Dcs 1100l FirmwareDcs 1130 Firmware+14 more
Nov 21, 2024
Jan 28, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1....Show more
An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU, DCS-2102 1.06_FR, DCS-2102 1.06, DCS-2102 1.05_RU, DCS-1130L 1.04, DCS-1130 1.04_US, DCS-1130 1.03, DCS-1100L 1.04, DCS-1100 1.04_US, and DCS-1100 1.03 due to hard-coded credentials that serve as a backdoor, which allows remote attackers to access the RTSP video stream.Show less
1Intelliantech
1Aptus
Jun 17, 2026
Jan 27, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account.