CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Security Identity Governance And Intelligence Nov 21, 2024 Feb 21, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound...Show more |
1Dasannetworks 1H665 Firmware Jun 17, 2026 Feb 20, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via TELNET. |
The Dell Wyse Password Encoder in ThinLinux2 versions prior to 2.1.0.01 contain a Hard-coded Cryptographic Key vulnerability. An unauthenticated remote attacker could reverse engineer the cryptographic system used in the...Show more |
1Cisco 1Network Assurance Engine Jun 17, 2026 Feb 12, 2019 N/A· v4 7.1 HIGH· v3 5.6 MEDIUM· v2 A vulnerability in the management web interface of Cisco Network Assurance Engine (NAE) could allow an unauthenticated, local attacker to gain unauthorized access or cause a Denial of Service (DoS) condition on the serve...Show more |
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. There is a default password of meinsm for the admin account. |
1Cisco 2Aironet Active Sensor Digital Network Architecture CenterJun 17, 2026 Feb 7, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in the default configuration of the Cisco Aironet Active Sensor could allow an unauthenticated, remote attacker to restart the sensor. The vulnerability is due to a default local account with a static pas...Show more |
LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high privileges. |
A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows an attacker to view the private data of all users of the Gua...Show more |
1Ibm 1Security Identity Manager Nov 21, 2024 Jan 24, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external compone...Show more |
Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could potentially be exploited by malicious use...Show more |
Premisys Identicard version 3.1.190 stores backup files as encrypted zip files. The password to the zip is hard-coded and unchangeable. An attacker with access to these backups can decrypt them and obtain sensitive data. |
Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password). |
Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents. |
1Juniper 1Advanced Threat Prevention Jun 17, 2026 Jan 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP:...Show more |
1Juniper 1Advanced Threat Prevention Jun 17, 2026 Jan 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP...Show more |
1Toshiba 2Hem Gw16a Firmware Hem Gw26a FirmwareNov 21, 2024 Jan 9, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segment to login to the administrators setti...Show more |
1Ricoh 8D2200 Firmware D5500 FirmwareD5510 Firmware+5 moreNov 21, 2024 Jan 9, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.1 to V2.2 attached (D5520, D6500, D6510, D7500, D8400),...Show more |
Battelle V2I Hub 2.5.1 contains hard-coded credentials for the administrative account. An attacker could exploit this vulnerability to log in as an admin on any installation and gain unauthorized access to the system. |
1Schneider Electric 1Evlink Parking Firmware Jun 17, 2026 Dec 24, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to the device. |
1Dlink 2Dir 140l Firmware Dir 640l FirmwareNov 21, 2024 Dec 21, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials. |