← Back
CWE-798

1,814 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,814)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Johnsoncontrols
1Metasys System
Jun 17, 2026
Aug 20, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).
1Swann
1Swwhd Intcam Hd Firmware
Nov 21, 2024
Aug 8, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31.
1Elmelectronics
1Elm27 Firmware
Jun 17, 2026
Jul 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle.
1Akuvox
1Sp R50p Firmware
Jun 17, 2026
Jul 22, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an attacker to get access to the device via telnet. The telnet service is running on port 2323; it cannot be turned off and the credentials cannot be c...Show more
Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an attacker to get access to the device via telnet. The telnet service is running on port 2323; it cannot be turned off and the credentials cannot be changed.Show less
1Audiocodes
4Median 500 Msbr Firmware
Median 500l Msbr FirmwareMedian 800c Msbr Firmware+1 more
Jun 17, 2026
Jul 20, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 all...Show more
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can authenticate with the default 1234 password that cannot be changed, and can execute malicious and unauthorized actions.Show less
1Cisco
2Findit Network Manager
Findit Network Probe
Jun 17, 2026
Jul 17, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account th...Show more
A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account that has root privileges. The vulnerability is due to the presence of an account with static credentials in the underlying Linux operating system. An attacker could exploit this vulnerability by logging in to the command line of the affected VM with the static account. A successful exploit could allow the attacker to log in with root-level privileges. This vulnerability affects only Cisco FindIT Network Manager and Cisco FindIT Network Probe Release 1.1.4 if these products are using Cisco-supplied VM images. No other releases or deployment models are known to be vulnerable.Show less
1Arlo
5Vmb3010 Firmware
Vmb3500 FirmwareVmb4000 Firmware+2 more
Jun 17, 2026
Jul 9, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to.
1Fortinet
1Fcm Mb40 Firmware
Jun 17, 2026
Jul 8, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation.
1Wolfvision
1Cynap
Jun 17, 2026
Jul 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorithm for calculating su...Show more
WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorithm for calculating support PINs, an attacker can reset the ADMIN password and thus gain remote access.Show less
1Invoxia
1Nvx220 Firmware
Nov 21, 2024
Jul 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Invoxia NVX220 devices allow TELNET access as admin with a default password.
1Amcrest
1Ipm 721s Firmware
Nov 21, 2024
Jul 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC0...Show more
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the default credentials on the device. If one opens this binary in IDA-pro, one will notice that this follows a ARM little endian format. The function sub_3DB2FC in IDA pro is identified to be setting up the values at address 0x003DB5A6. The sub_5C057C then sets this value and adds it to the Configuration files in /mnt/mtd/Config/Account1 file.Show less
1Dlink
2Dcs 1100 Firmware
Dcs 1130 Firmware
Nov 21, 2024
Jul 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x000...Show more
An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x00053894. Then performs a crypt operation on the password retrieved from the user at address 0x000538E0 and performs a strcmp at address 0x00053908 to check if the password is correct or incorrect. However, the /etc/shadow file is a part of CRAM-FS filesystem which means that the user cannot change the password and hence a hardcoded hash in /etc/shadow is used to match the credentials provided by the user. This is a salted hash of the string "admin" and hence it acts as a password to the device which cannot be changed as the whole filesystem is read only.Show less
1Nortekcontrol
2Linear Emerge Elite Firmware
Linear Emerge Essential Firmware
Jun 17, 2026
Jul 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Linear eMerge E3-Series devices have Hard-coded Credentials.
1Nortekcontrol
2Linear Emerge Elite Firmware
Linear Emerge Essential Firmware
Jun 17, 2026
Jul 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
1Sick
1Msc800 Firmware
Jun 17, 2026
Jul 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.
1Optergy
2Enterprise
Proton
Jun 17, 2026
Jul 1, 2019
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Optergy Proton/Enterprise devices have Hard-coded Credentials.
1Abb
16Cp620 Web Firmware
Cp620 FirmwareCp630 Web Firmware+13 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface...Show more
The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface and Tags (MODBUS coils) mapping to the HMI. These credentials are the idal123 password for the IdalMaster account, and the exor password for the exor account. These credentials are used over both HTTP(S) and FTP. There is no option to disable or change these undocumented credentials. An attacker can use these credentials to login to ABB HMI to read/write HMI configuration files and also to reset the device. This affects ABB CP635 HMI, CP600 HMIClient, Panel Builder 600, IDAL FTP server, IDAL HTTP server, and multiple other HMI components.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jun 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative...Show more
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper session management on affected DCNM software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to gain administrative access on the affected device.Show less
1Cylan
2Clever Dog Smart Camera Panorama Dog 2w Firmware
Clever Dog Smart Camera Plus Dog 2w V4 Firmware
Jun 17, 2026
Jun 20, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root a...Show more
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt.Show less
1Wago
3852 1305 Firmware
852 1505 Firmware852 303 Firmware
Jun 17, 2026
Jun 17, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.