← Back
CWE-798

1,814 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,814)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zingbox
1Inspector
Jun 17, 2026
Oct 9, 2019
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker to authenticate to the service using hard...Show more
The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker to authenticate to the service using hardcoded credentials.Show less
1Zingbox
1Inspector
Jun 17, 2026
Oct 9, 2019
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthorized users gaining access to the system.
1Broadcom
1Network Flow Analysis
Jun 17, 2026
Oct 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.
2Sandisk
Westerndigital
2Ssd Dashboard
Ssd Dashboard
Jun 17, 2026
Sep 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded password. An application update that addr...Show more
Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded password. An application update that addresses the protection of archive encryption is available.Show less
1Redlion
1Crimson
Jun 17, 2026
Sep 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may allow an attacker to access configuration...Show more
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may allow an attacker to access configuration files.Show less
1Westerndigital
1Wd My Book Firmware
Jun 17, 2026
Sep 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_a...Show more
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root password welc0me.Show less
1Telestar
11Bobs Rock Radio Firmware
Dabman D10 FirmwareDabman I30 Stereo Firmware+8 more
Jun 17, 2026
Sep 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have i...Show more
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have insufficient access control for the /set_dname, /mylogo, /LocalPlay, /irdevice.xml, /Sendkey, /setvol, /hotkeylist, /init, /playlogo.jpg, /stop, /exit, /back, and /playinfo commands.Show less
1Ifw8
5Fr5 E Firmware
Fr5 FirmwareFr6 S Firmware+2 more
Jun 17, 2026
Sep 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
1Philips
4Intellivue Mp Monitors Mp2/x2 Firmware
Intellivue Mp Monitors Mp20 Mp90 FirmwareIntellivue Mp Monitors Mp5/5sc Firmware+1 more
Jun 17, 2026
Sep 12, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN...Show more
Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C). An attacker can use these credentials to login via ftp and upload a malicious firmware.Show less
1Bosch
1Access
Jun 17, 2026
Sep 12, 2019
N/A· v4
9.9 CRITICAL· v3
6.5 MEDIUM· v2
Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edition (APE) 3.8.
2Auna
Telestar
12Bobs Rock Radio Firmware
Connect 100 FirmwareDabman D10 Firmware+9 more
Jun 17, 2026
Sep 11, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have a...Show more
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have an undocumented TELNET service within the BusyBox subsystem, leading to root access.Show less
1Omaksolutions
1Slick Popup
Jun 17, 2026
Sep 3, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.
1Equeshome
1Elf Smart Plug Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
The Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app. The communication happens over UDP port 27431. An attacker on the local ne...Show more
The Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app. The communication happens over UDP port 27431. An attacker on the local network can use the same key to encrypt and send commands to discover all smart plugs in a network, take over control of a device, and perform actions such as turning it on and off.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.
2Blackbox
Onelan
2Icompel Firmware
Net Top Box Firmware
Jun 17, 2026
Aug 26, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.
1Fortinet
1Fortirecorder Firmware
Jun 17, 2026
Aug 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take cont...Show more
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are managed by a FortiRecorder device.Show less
1Onelogin
1Onelogin Saml Sso
Nov 21, 2024
Aug 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
1Mirasys
1Mirasys Vms
Jun 17, 2026
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the ....Show more
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a serialized object) may be executed with SYSTEM privileges. The attacker must properly encrypt the object; however, the hardcoded keys are available.Show less
1Cisco
3Integrated Management Controller Supervisor
Ucs DirectorUcs Director Express For Big Data
Jun 17, 2026
Aug 21, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affec...Show more
A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials. The vulnerability is due to the presence of a documented default account with an undocumented default password and incorrect permission settings for that account. Changing the default password for this account is not enforced during the installation of the product. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the scpuser account. This includes full read and write access to the system's database.Show less
1Johnsoncontrols
1Metasys System
Jun 17, 2026
Aug 20, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).