← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wolfvision
1Cynap
Jun 17, 2026
Jul 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorithm for calculating su...Show more
WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorithm for calculating support PINs, an attacker can reset the ADMIN password and thus gain remote access.Show less
1Invoxia
1Nvx220 Firmware
Nov 21, 2024
Jul 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Invoxia NVX220 devices allow TELNET access as admin with a default password.
1Amcrest
1Ipm 721s Firmware
Nov 21, 2024
Jul 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC0...Show more
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the default credentials on the device. If one opens this binary in IDA-pro, one will notice that this follows a ARM little endian format. The function sub_3DB2FC in IDA pro is identified to be setting up the values at address 0x003DB5A6. The sub_5C057C then sets this value and adds it to the Configuration files in /mnt/mtd/Config/Account1 file.Show less
1Dlink
2Dcs 1100 Firmware
Dcs 1130 Firmware
Nov 21, 2024
Jul 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x000...Show more
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x00053894. Then performs a crypt operation on the password retrieved from the user at address 0x000538E0 and performs a strcmp at address 0x00053908 to check if the password is correct or incorrect. However, the /etc/shadow file is a part of CRAM-FS filesystem which means that the user cannot change the password and hence a hardcoded hash in /etc/shadow is used to match the credentials provided by the user. This is a salted hash of the string "admin" and hence it acts as a password to the device which cannot be changed as the whole filesystem is read only.Show less
1Nortekcontrol
2Linear Emerge Elite Firmware
Linear Emerge Essential Firmware
Jun 17, 2026
Jul 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Linear eMerge E3-Series devices have Hard-coded Credentials.
1Nortekcontrol
2Linear Emerge Elite Firmware
Linear Emerge Essential Firmware
Jun 17, 2026
Jul 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
1Sick
1Msc800 Firmware
Jun 17, 2026
Jul 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.
1Optergy
2Enterprise
Proton
Jun 17, 2026
Jul 1, 2019
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Optergy Proton/Enterprise devices have Hard-coded Credentials.
1Abb
16Cp620 Web Firmware
Cp620 FirmwareCp630 Web Firmware+13 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface...Show more
The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface and Tags (MODBUS coils) mapping to the HMI. These credentials are the idal123 password for the IdalMaster account, and the exor password for the exor account. These credentials are used over both HTTP(S) and FTP. There is no option to disable or change these undocumented credentials. An attacker can use these credentials to login to ABB HMI to read/write HMI configuration files and also to reset the device. This affects ABB CP635 HMI, CP600 HMIClient, Panel Builder 600, IDAL FTP server, IDAL HTTP server, and multiple other HMI components.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jun 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative...Show more
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper session management on affected DCNM software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to gain administrative access on the affected device.Show less
1Cylan
2Clever Dog Smart Camera Panorama Dog 2w Firmware
Clever Dog Smart Camera Plus Dog 2w V4 Firmware
Jun 17, 2026
Jun 20, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root a...Show more
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt.Show less
1Wago
3852 1305 Firmware
852 1505 Firmware852 303 Firmware
Jun 17, 2026
Jun 17, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.
1Wago
3852 1305 Firmware
852 1505 Firmware852 303 Firmware
Jun 17, 2026
Jun 17, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedd...Show more
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.Show less
1Enttec
4Datagate Mk2 Firmware
E Streamer Mk2 FirmwarePixelator Firmware+1 more
Jun 17, 2026
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user....Show more
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user. A command in the relocate and relocate_revB scripts copies the hardcoded key to the root user's authorized_keys file, enabling anyone with the associated private key to gain remote root access to all affected products.Show less
1Ibm
2Infosphere Information Server On Cloud
Watson Knowledge Catalog
Jun 17, 2026
Jun 6, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force ID: 159229.
1Primasystems
1Flexair
Jun 17, 2026
Jun 5, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow an authenticated attacker to escalate privileges.
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
A remote credential disclosure vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
1Ivanti
1Landesk Management Suite
Jun 17, 2026
Jun 3, 2019
N/A· v4
4.5 MEDIUM· v3
2.7 LOW· v2
Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges.
1Orpak
1Siteomat
Jun 2, 2026
Jun 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to swit...Show more
An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to switch passwords, leaving SSH and HTTP remote authentication open to public.Show less