← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Engineering Lifecycle Optimization Publishing
Mar 25, 2025
Mar 2, 2018
N/A· v4
6.7 MEDIUM· v3
2.1 LOW· v2
IBM Publishing Engine 2.1.2 and 6.0.5 contains an undisclosed vulnerability that could allow a local user with administrative privileges to obtain hard coded user credentials. IBM X-Force ID: 137022.
1Wowza
1Streaming Engine
Jun 17, 2026
Mar 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the default JMX credentials (remote code execution may be possible as well).
1
1Wireless Ip Camera 360
Nov 21, 2024
Feb 26, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on Wireless IP Camera 360 devices. Remote attackers can discover a weakly encoded admin password by connecting to TCP port 9527 and reading the password field of the debugging information, e.g., n...Show more
An issue was discovered on Wireless IP Camera 360 devices. Remote attackers can discover a weakly encoded admin password by connecting to TCP port 9527 and reading the password field of the debugging information, e.g., nTBCS19C corresponds to a password of 123456.Show less
1
1Wireless Ip Camera 360
Nov 21, 2024
Feb 26, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on Wireless IP Camera 360 devices. A root account with a known SHA-512 password hash exists, which makes it easier for remote attackers to obtain administrative access via a TELNET session.
1Seagate
2Blackarmor Nas 110 Firmware
Blackarmor Nas 220 Firmware
Nov 21, 2024
Feb 23, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
1Datto
8Alto 2 Firmware
Alto 3 FirmwareAlto Imaged Firmware+5 more
Nov 21, 2024
Feb 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Datto ALTO and SIRIS devices have a default VNC password.
1Smiths Medical
1Medfusion 4000 Wireless Syringe Infusion Pump
Nov 21, 2024
Feb 15, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
A Use of Hard-coded Password issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. Telnet on the pump uses hardcoded credentials, which can be used if the pump i...Show more
A Use of Hard-coded Password issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. Telnet on the pump uses hardcoded credentials, which can be used if the pump is configured to allow external communications. Smiths Medical assesses that it is not possible to upload files via Telnet and the impact of this vulnerability is limited to the communications module.Show less
1Smiths Medical
1Medfusion 4000 Wireless Syringe Infusion Pump
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump with default network configuration uses hard-coded credentials to...Show more
A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump with default network configuration uses hard-coded credentials to automatically establish a wireless network connection. The pump will establish a wireless network connection even if the pump is Ethernet connected and active; however, if the wireless association is established and the Ethernet cable is attached, the pump does not attach the network stack to the wireless network. In this scenario, all network traffic is instead directed over the wired Ethernet connection.Show less
1Smiths Medical
1Medfusion 4000 Wireless Syringe Infusion Pump
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The FTP server on the pump contains hardcoded credentials, which are not fu...Show more
A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The FTP server on the pump contains hardcoded credentials, which are not fully initialized. The FTP server is only accessible if the pump is configured to allow FTP connections.Show less
1Dell
1Emc Supportassist Enterprise
Nov 21, 2024
Feb 12, 2018
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after...Show more
Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after an upgrade from v1.1 to v1.2. Access to the management console can be achieved by someone with knowledge of the default password. If SupportAssist Enterprise is installed on a server running OpenManage Essentials (OME), the OmeAdapterUser user account is added as a member of the OmeAdministrators group for the OME. An unauthorized person with knowledge of the default password and access to the OME web console could potentially use this account to gain access to the affected installation of OME with OmeAdministrators privileges. This is fixed in version 1.2.1.Show less
1Omninova
1Vobot Firmware
Jun 17, 2026
Feb 9, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on VOBOT CLOCK before 0.99.30 devices. An SSH server exists with a hardcoded vobot account that has root access.
1Ibm
4Xiv Storage System 2810 114 Firmware
Xiv Storage System 2810 A14 FirmwareXiv Storage System 2812 114 Firmware+1 more
Nov 21, 2024
Feb 8, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded passwords for unspecified accounts, which allows remote attackers to gain...Show more
IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded passwords for unspecified accounts, which allows remote attackers to gain user access via unknown vectors. IBM X-Force ID: 75041.Show less
1Web2py
1Web2py
Nov 21, 2024
Feb 6, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a hardcoded encryption key when calling the session.connect function.
1Extremenetworks
1Extremewireless Wing
Jun 17, 2026
Feb 5, 2018
N/A· v4
7.5 HIGH· v3
3.3 LOW· v2
An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES Key that can be used for packet decryption (obtaining cleartext creden...Show more
An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES Key that can be used for packet decryption (obtaining cleartext credentials) by an attacker who has access to a wired port.Show less
1Iball
1Ib Wra150n Firmware
Jun 17, 2026
Jan 29, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardcoded password of support for the support account, and a hardcoded password of user for the user acco...Show more
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardcoded password of support for the support account, and a hardcoded password of user for the user account.Show less
1Ibm
1Tealeaf Customer Experience
Nov 21, 2024
Jan 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 contains hard-coded credentials. A remote attacker could exploit this vulnerability to gain access to the system. IBM X-Force ID: 123740.
1Lenovo
1Fingerprint Manager Pro
Nov 21, 2024
Jan 26, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password,...Show more
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is installed.Show less
1Barni
1Master Ip Camera01 Firmware
Jun 17, 2026
Jan 16, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server.
1Barni
1Master Ip Camera01 Firmware
Jun 17, 2026
Jan 16, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.
1Trendnet
1Tew 823dru Firmware
Nov 21, 2024
Jan 5, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account, which makes it easier for remote attackers to obtain access via an FTP session.