CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system relies on the client binary to enforce security rules and integrity of...Show more |
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists. |
1Polycom 2Better Together Over Ethernet Connector Unified Communications SoftwareJun 17, 2026 Apr 23, 2019 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard-coded credentials to establish connections between the host applicatio...Show more |
1Xinruidz 1Sundray Wan Controller Firmware Jun 17, 2026 Apr 18, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a backdoor account allowing a remote attacker to login to the system via SSH (on TCP port 22345) and escalate to root (because the password for r...Show more |
1Dasannetworks 1H660rm Firmware Jun 17, 2026 Apr 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by anyone able to access this key. |
1Glory Global 1Rbw 100 Firmware Jun 17, 2026 Apr 5, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. A hard-coded username and password were identified that allow a remote attacker to gain admin access to the Front Circle Controller web int...Show more |
Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying application using undocumented, pre-installed X.509v3 key/certificate pairs. An unauthenticated remote atta...Show more |
1Baxter 1Sigma Spectrum Infusion System Firmware Nov 21, 2024 Mar 26, 2019 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contains a hard-coded password, which provides access to basic biomedical information, limited device sett...Show more |
1Baxter 1Sigma Spectrum Infusion System Firmware Nov 21, 2024 Mar 26, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with hard-coded credentials used with the FTP protocol. Baxter asserts no files can...Show more |
1Jenzabar 1Internet Campus Solution Jun 17, 2026 Mar 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attackers to create an arbitrary number of accounts with a password of 1234. |
1Pifzer 3Plum A+3 Infusion System Firmware Plum A+ Infusion System FirmwareSymbiq Infusion System FirmwareNov 21, 2024 Mar 25, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends th...Show more |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data. |
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. The tools/ping Ping feature of the Diagnostic Tools component is vulnerable to Remote Command Execution, allowing an attacker to execute arb...Show more |
An issue was discovered on Wifi-soft UniBox controller 3.x devices. The tools/controller/diagnostic_tools_controller Diagnostic Tools Controller is vulnerable to Remote Command Execution, allowing an attacker to execute...Show more |
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, allowing an attacker to upload .php files and execute code on the server w...Show more |
1Teracue 3Enc 400 Hdmi2 Firmware Enc 400 Hdmi FirmwareEnc 400 Hdsdi FirmwareNov 21, 2024 Mar 21, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web admini...Show more |
1Patlite 3Nbm D88n Firmware Nhl 3fb1 FirmwareNhl 3fv1n FirmwareNov 21, 2024 Mar 21, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow atta...Show more |
EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application. |
1Cisco 1Common Services Platform Collector Jun 17, 2026 Mar 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device by using an account that has a default, static password. This account do...Show more |
1Nokia 1I 240w Q Gpon Ont Firmware Jun 17, 2026 Mar 5, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces. |