← Back
CWE-798

1,814 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,814)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intelliantech
1Aptus Web
Jun 17, 2026
Jan 27, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.
1Intelliantech
1Aptus
Jun 17, 2026
Jan 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.
1Gehealthcare
6Apexpro Telemetry Server Firmware
Carescape Central Station Mai700 FirmwareCarescape Central Station Mas700 Firmware+3 more
Jun 17, 2026
Jan 24, 2020
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products ut...Show more
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.Show less
1Fortinet
1Fortisiem
Jun 17, 2026
Jan 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.
1Taskautomation
1Carbonftp
Jun 17, 2026
Jan 21, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary.
1Mycarcontrols
1Mycar Controls
Jun 17, 2026
Jan 15, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The MyCar Controls of AutoMobility Distribution Inc., mobile application contains hard-coded admin credentials. A remote unauthenticated attacker may be able to send commands to and retrieve data from a target MyCar unit...Show more
The MyCar Controls of AutoMobility Distribution Inc., mobile application contains hard-coded admin credentials. A remote unauthenticated attacker may be able to send commands to and retrieve data from a target MyCar unit. This may allow the attacker to learn the location of a target, or gain unauthorized physical access to a vehicle. This issue affects AutoMobility MyCar versions prior to 3.4.24 on iOS and versions prior to 4.1.2 on Android. This issue has additionally been fixed in Carlink, Link, Visions MyCar, and MyCar Kia.Show less
1Abb
8Cp651 Web Firmware
Cp651 FirmwareCp661 Web Firmware+5 more
Jun 17, 2026
Jan 14, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the HMI interface.
1Billion
1Sg600 R2 Firmware
Jun 17, 2026
Jan 9, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hardcoded credentials into a shell, gaining root execution privileges over...Show more
An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hardcoded credentials into a shell, gaining root execution privileges over the device.Show less
1Redhat
2Keycloak
Single Sign On
Jun 17, 2026
Jan 7, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client...Show more
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be 'service-account-test@placeholder.org'.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 6, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administra...Show more
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 6, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administra...Show more
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 6, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administra...Show more
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
2Citrix
Supermicro
5Netscaler Firmware
Netscaler Sd Wan FirmwareNetscaler Sdx Firmware+2 more
Nov 21, 2024
Jan 2, 2020
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private...Show more
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.Show less
1Barco
3Clickshare Cs 100 Firmware
Clickshare Cse 200 FirmwareClickshare Cse 800 Firmware
Jun 17, 2026
Dec 16, 2019
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button firmware contains the private key of a test device-certificate.
2Petwant
Skymee
2Petalk Ai Firmware
Pf 103 Firmware
Jun 17, 2026
Dec 13, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
3Debian
PuppetRedhat
3Debian Linux
Marionette CollectiveOpenshift
Nov 21, 2024
Dec 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
mcollective has a default password set at install
1Puppet
1Puppet Enterprise
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password...Show more
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise 2019.0.3 and 2018.1.9.Show less
1Amazon
1Blink Xt2 Sync Module Firmware
Jun 17, 2026
Dec 11, 2019
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections.
1Grandstream
13Gxv3500 Firmware
Gxv3501 FirmwareGxv3504 Firmware+10 more
Nov 21, 2024
Dec 11, 2019
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account "!#/" with th...Show more
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account "!#/" with the same password, which makes it easier for remote attackers to obtain access via a TELNET session.Show less
1Titanhq
1Webtitan
Jun 17, 2026
Dec 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this accou...Show more
An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.Show less