← Back
CWE-798

1,814 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,814)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Identicard
1Premisys Id
Jun 17, 2026
Jan 18, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents.
1Juniper
1Advanced Threat Prevention
Jun 17, 2026
Jan 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP:...Show more
Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.Show less
1Juniper
1Advanced Threat Prevention
Jun 17, 2026
Jan 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP...Show more
Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.Show less
1Toshiba
2Hem Gw16a Firmware
Hem Gw26a Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segment to login to the administrators setti...Show more
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segment to login to the administrators settings screen and change the configuration or execute arbitrary OS commands.Show less
1Ricoh
8D2200 Firmware
D5500 FirmwareD5510 Firmware+5 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.1 to V2.2 attached (D5520, D6500, D6510, D7500, D8400),...Show more
RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.1 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display versions with RICOH Interactive Whiteboard Controller Type2 V3.0 to V3.1.10137.0 attached (D5520, D6510, D7500, D8400) uses hard-coded credentials, which may allow an attacker on the same network segments to login to the administrators settings screen and change the configuration.Show less
1Battelle
1V2i Hub
Nov 21, 2024
Dec 28, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Battelle V2I Hub 2.5.1 contains hard-coded credentials for the administrative account. An attacker could exploit this vulnerability to log in as an admin on any installation and gain unauthorized access to the system.
1Schneider Electric
1Evlink Parking Firmware
Jun 17, 2026
Dec 24, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to the device.
1Dlink
2Dir 140l Firmware
Dir 640l Firmware
Nov 21, 2024
Dec 21, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials.
1Dlink
7Dir 140l Firmware
Dir 640l FirmwareDsl 2770l Firmware+4 more
Nov 21, 2024
Dec 21, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials.
1Dlink
1Dsl 2770l Firmware
Nov 21, 2024
Dec 21, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
atbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials.
1Logitech
1Harmony Hub Firmware
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.
1Comparex
1Miss Marple
Nov 21, 2024
Dec 20, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
COMPAREX Miss Marple Enterprise Edition before 2.0 allows local users to execute arbitrary code by reading the user name and encrypted password hard-coded in an Inventory Agent configuration file.
1Ricoh
1Myprint
Nov 21, 2024
Dec 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of related Google clou...Show more
Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of related Google cloud printers, encrypted passwords of mail servers, and names of printed files.Show less
1Ibm
1Security Access Manager
Nov 21, 2024
Dec 13, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound c...Show more
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 152078.Show less
1Ibm
1Security Guardium
Nov 21, 2024
Dec 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption o...Show more
IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 150022.Show less
1Ibm
1Qradar Incident Forensics
Nov 21, 2024
Dec 5, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. IBM X-Force ID: 144656.
1Cisco
1Energy Management Suite
Nov 21, 2024
Dec 4, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A vulnerability in the configuration of a local database installed as part of the Cisco Energy Management Suite (CEMS) could allow an authenticated, local attacker to access and alter confidential data. The vulnerability...Show more
A vulnerability in the configuration of a local database installed as part of the Cisco Energy Management Suite (CEMS) could allow an authenticated, local attacker to access and alter confidential data. The vulnerability is due to the installation of the PostgreSQL database with unchanged default access credentials. An attacker could exploit this vulnerability by logging in to the machine where CEMS is installed and establishing a local connection to the database. The fix for this vulnerability randomizes the database access password in new installations; however, the fix will not change the password for existing installations. Users are required to manually change the password, as documented in the Workarounds section of this advisory. There are workarounds that address this vulnerability.Show less
1Lenovo
1System Management Module Firmware
Jun 17, 2026
Nov 27, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via s...Show more
In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.Show less
1Lenovo
1Chassis Management Module Firmware
Jun 17, 2026
Nov 16, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt...Show more
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.Show less
1Neo
2Debun Imap
Debun Pop
Nov 21, 2024
Nov 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to login to the Management page and change the...Show more
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to login to the Management page and change the configuration.Show less