← Back
CWE-798

1,814 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,814)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Indionetworks
1Unibox Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. The tools/ping Ping feature of the Diagnostic Tools component is vulnerable to Remote Command Execution, allowing an attacker to execute arb...Show more
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. The tools/ping Ping feature of the Diagnostic Tools component is vulnerable to Remote Command Execution, allowing an attacker to execute arbitrary system commands on the server with root user privileges. Authentication for accessing this component can be bypassed by using Hard coded credentials.Show less
1Indionetworks
1Unibox Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered on Wifi-soft UniBox controller 3.x devices. The tools/controller/diagnostic_tools_controller Diagnostic Tools Controller is vulnerable to Remote Command Execution, allowing an attacker to execute...Show more
An issue was discovered on Wifi-soft UniBox controller 3.x devices. The tools/controller/diagnostic_tools_controller Diagnostic Tools Controller is vulnerable to Remote Command Execution, allowing an attacker to execute arbitrary system commands on the server with root user privileges. Authentication for accessing this component can be bypassed by using Hard coded credentials.Show less
1Indionetworks
1Unibox Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, allowing an attacker to upload .php files and execute code on the server w...Show more
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, allowing an attacker to upload .php files and execute code on the server with root user privileges. Authentication for accessing this component can be bypassed by using Hard coded credentials.Show less
1Teracue
3Enc 400 Hdmi2 Firmware
Enc 400 Hdmi FirmwareEnc 400 Hdsdi Firmware
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web admini...Show more
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web administration panel. This token is hard-coded to a string in the source code (/usr/share/www/check.lp file). By setting this cookie in a browser, an attacker is able to maintain access to every ENC-400 device without knowing the password, which results in authentication bypass. Even if a user changes the password on the device, this token is static and unchanged.Show less
1Patlite
3Nbm D88n Firmware
Nhl 3fb1 FirmwareNhl 3fv1n Firmware
Nov 21, 2024
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow atta...Show more
A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow attackers to enable an SSH daemon via the "kankichi" or "kamiyo4" password to the _secret1.htm URI. Subsequently, the default password of root for the root account allows an attacker to conduct remote code execution and as a result take over the system.Show less
1Hidglobal
1Easylobby Solo
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.
1Cisco
1Common Services Platform Collector
Jun 17, 2026
Mar 13, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device by using an account that has a default, static password. This account do...Show more
A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device by using an account that has a default, static password. This account does not have administrator privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to the affected system using this account. A successful exploit could allow the attacker to log in to the CSPC using the default account. For Cisco CSPC 2.7.x, Cisco fixed this vulnerability in Release 2.7.4.6. For Cisco CSPC 2.8.x, Cisco fixed this vulnerability in Release 2.8.1.2.Show less
1Nokia
1I 240w Q Gpon Ont Firmware
Jun 17, 2026
Mar 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces.
1Ibm
1Security Identity Governance And Intelligence
Nov 21, 2024
Feb 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound...Show more
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 153386.Show less
1Dasannetworks
1H665 Firmware
Jun 17, 2026
Feb 20, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via TELNET.
1Dell
1Wyse Thinlinux
Nov 21, 2024
Feb 13, 2019
N/A· v4
8.0 HIGH· v3
7.9 HIGH· v2
The Dell Wyse Password Encoder in ThinLinux2 versions prior to 2.1.0.01 contain a Hard-coded Cryptographic Key vulnerability. An unauthenticated remote attacker could reverse engineer the cryptographic system used in the...Show more
The Dell Wyse Password Encoder in ThinLinux2 versions prior to 2.1.0.01 contain a Hard-coded Cryptographic Key vulnerability. An unauthenticated remote attacker could reverse engineer the cryptographic system used in the Dell Wyse Password Encoder to discover the hard coded private key and decrypt locally stored cipher text.Show less
1Cisco
1Network Assurance Engine
Jun 17, 2026
Feb 12, 2019
N/A· v4
7.1 HIGH· v3
5.6 MEDIUM· v2
A vulnerability in the management web interface of Cisco Network Assurance Engine (NAE) could allow an unauthenticated, local attacker to gain unauthorized access or cause a Denial of Service (DoS) condition on the serve...Show more
A vulnerability in the management web interface of Cisco Network Assurance Engine (NAE) could allow an unauthenticated, local attacker to gain unauthorized access or cause a Denial of Service (DoS) condition on the server. The vulnerability is due to a fault in the password management system of NAE. An attacker could exploit this vulnerability by authenticating with the default administrator password via the CLI of an affected server. A successful exploit could allow the attacker to view potentially sensitive information or bring the server down, causing a DoS condition. This vulnerability affects Cisco Network Assurance Engine (NAE) Release 3.0(1). The default password condition only affects new installations of Release 3.0(1).Show less
1Mobotix
1S14 Firmware
Nov 21, 2024
Feb 9, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. There is a default password of meinsm for the admin account.
1Cisco
2Aironet Active Sensor
Digital Network Architecture Center
Jun 17, 2026
Feb 7, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A vulnerability in the default configuration of the Cisco Aironet Active Sensor could allow an unauthenticated, remote attacker to restart the sensor. The vulnerability is due to a default local account with a static pas...Show more
A vulnerability in the default configuration of the Cisco Aironet Active Sensor could allow an unauthenticated, remote attacker to restart the sensor. The vulnerability is due to a default local account with a static password. The account has privileges only to reboot the device. An attacker could exploit this vulnerability by guessing the account name and password to access the CLI. A successful exploit could allow the attacker to reboot the device repeatedly, creating a denial of service (DoS) condition. It is not possible to change the configuration or view sensitive data with this account. Versions prior to DNAC1.2.8 are affected.Show less
1Lcds
1Laquis Scada
Nov 21, 2024
Feb 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high privileges.
1Guardzilla
1Gz521w Firmware
Jun 17, 2026
Jan 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows an attacker to view the private data of all users of the Gua...Show more
A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows an attacker to view the private data of all users of the Guardzilla device.Show less
1Ibm
1Security Identity Manager
Nov 21, 2024
Jan 24, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external compone...Show more
IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 153633.Show less
1Teradata
1Viewpoint
Jun 17, 2026
Jan 21, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could potentially be exploited by malicious use...Show more
Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could potentially be exploited by malicious users to compromise the affected system.Show less
1Identicard
1Premisys Id
Jun 17, 2026
Jan 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Premisys Identicard version 3.1.190 stores backup files as encrypted zip files. The password to the zip is hard-coded and unchangeable. An attacker with access to these backups can decrypt them and obtain sensitive data.
1Identicard
1Premisys Id
Jun 17, 2026
Jan 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).