CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie a...Show more |
1Lutron 3Homeworks Qs Firmware Radiora 2 FirmwareStanza FirmwareNov 21, 2024 Jun 2, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integration protocol Revision M to Revision Y. NO...Show more |
1Lutron 3Homeworks Qs Firmware Radiora 2 FirmwareStanza FirmwareNov 21, 2024 Jun 2, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol...Show more |
1Lutron 3Homeworks Qs Firmware Radiora 2 FirmwareStanza FirmwareNov 21, 2024 Jun 2, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the HomeWorks QS Lutron integrat...Show more |
1Tp Link 4Ipc Tl Ipc223(p) 6 Firmware Tl Ipc323k D FirmwareTl Ipc325(kp) Firmware+1 moreNov 21, 2024 May 30, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 /usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 password. |
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these c...Show more |
1Cisco 1Digital Network Architecture Center Nov 21, 2024 May 17, 2018 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by using an administrative account that has default, static user credenti...Show more |
1Intelbras 1Ncloud 300 Firmware Nov 21, 2024 May 15, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST...Show more |
1Foxconn 1Ap Fc4064 T Firmware Jun 17, 2026 May 10, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In addition, its web management page relies on the existence or values of...Show more |
1Redlion 2Sixnet Managed Industrial Switches Firmware Stride Managed Ethernet Switches FirmwareNov 21, 2024 May 9, 2018 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 and Stride-Managed Ethernet Switches running firmware Version 5.0.190....Show more |
The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell. |
The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shell. |
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql. |
1Philips 4 Brilliance Ct Big Bore Firmware Brilliance Firmware 64Brilliance Ict Firmware+1 moreJun 17, 2026 May 4, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Philips Brilliance CT software (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bore 2.3.5 and prior) contains fixed creden...Show more |
The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptographic key, so anyone who knows that key and the algorithm can...Show more |
Meross MSS110 devices before 1.1.24 contain a TELNET listener providing access for an undocumented admin account with a blank password. |
1Bostonscientific 1Zoom Latitude Prm 3120 Firmware Nov 21, 2024 May 1, 2018 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Boston Scientific ZOOM LATITUDE PRM Model 3120 uses a hard-coded cryptographic key to encrypt PHI prior to having it transferred to removable media. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:...Show more |
1Watchguard 3Ap100 Firmware Ap102 FirmwareAp200 FirmwareNov 21, 2024 Apr 30, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false. |
The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a database account with privileges that can affect confidentiality, integrity, and availab...Show more |
1Momentum 1Momentum Axel 720p Firmware Nov 21, 2024 Apr 24, 2018 N/A· v4 7.4 HIGH· v3 3.3 LOW· v2 Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote attackers to view the RTSP video stream. |