← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Symantec
1Norton Password Manager
Nov 21, 2024
Aug 29, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data...Show more
The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials.Show less
1Npci
1Bharat Interface For Money (bhim)
Nov 21, 2024
Aug 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authen...Show more
The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authentication.Show less
1Planex
2Cs Qr20 Firmware
Smacam Night Vision
Nov 21, 2024
Aug 24, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on the PLANEX CS-QR20 1.30. A hardcoded account / password ("admin:password") is used in the Android application that allows attackers to use a hidden API URL "/goform/SystemCommand" to execute an...Show more
An issue was discovered on the PLANEX CS-QR20 1.30. A hardcoded account / password ("admin:password") is used in the Android application that allows attackers to use a hidden API URL "/goform/SystemCommand" to execute any command with root permission.Show less
1Planex
1Cs W50hd Firmware
Nov 21, 2024
Aug 24, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. A hardcoded credential "supervisor:dangerous" was injected into web authentication database "/.htpasswd" during booting process, which allow...Show more
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. A hardcoded credential "supervisor:dangerous" was injected into web authentication database "/.htpasswd" during booting process, which allows attackers to gain unauthorized access and control the device completely; the account can't be modified or deleted.Show less
1Posim
1Evo
Nov 21, 2024
Aug 23, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM EVO's database may result in a breach of confidentiality, integrity, or availability or allow for a...Show more
POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM EVO's database may result in a breach of confidentiality, integrity, or availability or allow for attackers to remotely execute code on associated POSIM EVO clients.Show less
1Philips
5Pagewriter Tc10 Firmware
Pagewriter Tc20 FirmwarePagewriter Tc30 Firmware+2 more
Nov 21, 2024
Aug 22, 2018
N/A· v4
6.2 MEDIUM· v3
7.2 HIGH· v2
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to acces...Show more
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to access and modify all settings on the device, as well as allow the user to reset existing passwords.Show less
1Zemana
1Antilogger
Nov 21, 2024
Aug 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to take control of the whitelisting feature (MyRules2.ini under %LOCALAPPD...Show more
A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to take control of the whitelisting feature (MyRules2.ini under %LOCALAPPDATA%\Zemana\ZALSDK) to permit execution of unauthorized applications (such as ones that record keystrokes).Show less
1Eltex
1Esp 200 Firmware
Nov 21, 2024
Aug 17, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0.
1Asustor
1Asustor Data Master
Nov 21, 2024
Aug 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a...Show more
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.Show less
1Psafe
1Dfndr Security
Nov 21, 2024
Aug 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DFNDR Security Antivirus, Anti-hacking & Cleaner, 5.0.9, 2017-11-01, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
1Liveme
1Liveme
Nov 21, 2024
Aug 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Live.me - live stream video chat, 3.7.20, 2017-11-06, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
1Cmcm
1Cm Launcher 3d
Nov 21, 2024
Aug 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cheetahmobile CM Launcher 3D - Theme, wallpaper, Secure, Efficient, 5.0.3, 2017-09-19, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this k...Show more
Cheetahmobile CM Launcher 3D - Theme, wallpaper, Secure, Efficient, 5.0.3, 2017-09-19, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.Show less
1Uber
1Ubereats
Nov 21, 2024
Aug 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Uber Technologies, Inc. UberEATS: Uber for Food Delivery, 1.108.10001, 2017-11-02, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
1Gameloft
1Asphalt Xtreme
Nov 21, 2024
Aug 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Gameloft Asphalt Xtreme: Offroad Rally Racing, 1.6.0, 2017-08-13, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
1Tiktok
1Musical.ly
Nov 21, 2024
Aug 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
1Distinctdev
1The Moron Test
Nov 21, 2024
Aug 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
1Harmonicinc
1Nsg 9000 Firmware
Nov 21, 2024
Aug 5, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Harmonic NSG 9000 devices have a default password of nsgadmin for the admin account, a default password of nsgguest for the guest account, and a default password of nsgconfig for the config account.
1Yokogawa
4Fcj Firmware
Fcn 100 FirmwareFcn 500 Firmware+1 more
Nov 21, 2024
Jul 31, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attac...Show more
Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attacker to gain unauthorized administrative access to the device, which could result in remote code execution.Show less
2Openstack
Redhat
2Openstack
Tripleo Heat Templates
Nov 21, 2024
Jul 30, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credent...Show more
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.Show less
2Ibm
Lenovo
42Bladecenter Hs22 Firmware
Bladecenter Hs23 FirmwareBladecenter Hs23e Firmware+39 more
Jun 17, 2026
Jul 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on...Show more
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and earlier than 6.80 for IBM System x, the credentials to access the SFTP server are hard-coded and described in the IMM2 documentation, allowing an attacker with management network access to obtain the collected FFDC data. After applying the update, the IMM2 will create random SFTP credentials for use with OneCLI.Show less