CWE-798
1,814 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,814)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Johnsoncontrols 1Metasys System Jun 17, 2026 Aug 20, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP). |
1Swann 1Swwhd Intcam Hd Firmware Nov 21, 2024 Aug 8, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31. |
1Elmelectronics 1Elm27 Firmware Jun 17, 2026 Jul 31, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle. |
Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an attacker to get access to the device via telnet. The telnet service is running on port 2323; it cannot be turned off and the credentials cannot be c...Show more |
1Audiocodes 4Median 500 Msbr Firmware Median 500l Msbr FirmwareMedian 800c Msbr Firmware+1 moreJun 17, 2026 Jul 20, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 all...Show more |
1Cisco 2Findit Network Manager Findit Network ProbeJun 17, 2026 Jul 17, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account th...Show more |
1Arlo 5Vmb3010 Firmware Vmb3500 FirmwareVmb4000 Firmware+2 moreJun 17, 2026 Jul 9, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to. |
Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation. |
WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorithm for calculating su...Show more |
Invoxia NVX220 devices allow TELNET access as admin with a default password. |
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC0...Show more |
1Dlink 2Dcs 1100 Firmware Dcs 1130 FirmwareNov 21, 2024 Jul 2, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x000...Show more |
1Nortekcontrol 2Linear Emerge Elite Firmware Linear Emerge Essential FirmwareJun 17, 2026 Jul 2, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Linear eMerge E3-Series devices have Hard-coded Credentials. |
1Nortekcontrol 2Linear Emerge Elite Firmware Linear Emerge Essential FirmwareJun 17, 2026 Jul 2, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH). |
SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password. |
Optergy Proton/Enterprise devices have Hard-coded Credentials. |
1Abb 16Cp620 Web Firmware Cp620 FirmwareCp630 Web Firmware+13 moreJun 17, 2026 Jun 27, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jun 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative...Show more |
1Cylan 2Clever Dog Smart Camera Panorama Dog 2w Firmware Clever Dog Smart Camera Plus Dog 2w V4 FirmwareJun 17, 2026 Jun 20, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root a...Show more |
1Wago 3852 1305 Firmware 852 1505 Firmware852 303 FirmwareJun 17, 2026 Jun 17, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET. |