← Back
CWE-798

1,812 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,812)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Telesquare
2Sdt Cs3b1 Firmware
Sdt Cw3b1 Firmware
Nov 21, 2024
Jun 21, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET using a hardcoded account.
1D Link
1Dir 620 Firmware
Jun 17, 2026
Jun 20, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, there is a hardcoded password of anonymous for the admin account.
1Dlink
1Dir 620 Firmware
Jun 17, 2026
Jun 19, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which makes it easier for remote attackers to obtain access via a TELNET session.
1Apollotechnologiesinc
2Momentum Axel 720p
Momentum Axel 720p Firmware
Nov 21, 2024
Jun 13, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easier for physically proximate attackers to login at the console.
1Cisco
1Wide Area Application Services
Nov 21, 2024
Jun 7, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to read data f...Show more
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to a hard-coded, read-only community string in the configuration file for the SNMP daemon. An attacker could exploit this vulnerability by using the static community string in SNMP version 2c queries to an affected device. A successful exploit could allow the attacker to read any data that is accessible via SNMP on the affected device. Note: The static credentials are defined in an internal configuration file and are not visible in the current operation configuration ('running-config') or the startup configuration ('startup-config'). Cisco Bug IDs: CSCvi40137.Show less
1Gamerpolls
1Gamerpolls
Nov 21, 2024
Jun 5, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of t...Show more
An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of the account they wish to take over, and re-sign it using the hard coded secret.Show less
1Aprendecondedos
1Dedos Web
Nov 21, 2024
Jun 5, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie a...Show more
In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of Passport.js, this could lead to privilege escalation.Show less
1Lutron
3Homeworks Qs Firmware
Radiora 2 FirmwareStanza Firmware
Nov 21, 2024
Jun 2, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integration protocol Revision M to Revision Y. NO...Show more
Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machineShow less
1Lutron
3Homeworks Qs Firmware
Radiora 2 FirmwareStanza Firmware
Nov 21, 2024
Jun 2, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol...Show more
Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machineShow less
1Lutron
3Homeworks Qs Firmware
Radiora 2 FirmwareStanza Firmware
Nov 21, 2024
Jun 2, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the HomeWorks QS Lutron integrat...Show more
Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the HomeWorks QS Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machineShow less
1Tp Link
4Ipc Tl Ipc223(p) 6 Firmware
Tl Ipc323k D FirmwareTl Ipc325(kp) Firmware+1 more
Nov 21, 2024
May 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
/usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 password.
1Myscada
1Mypro
Nov 21, 2024
May 20, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these c...Show more
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.Show less
1Cisco
1Digital Network Architecture Center
Nov 21, 2024
May 17, 2018
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by using an administrative account that has default, static user credenti...Show more
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by using an administrative account that has default, static user credentials. The vulnerability is due to the presence of undocumented, static user credentials for the default administrative account for the affected software. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands with root privileges. This vulnerability affects all releases of Cisco DNA Center Software prior to Release 1.1.3. Cisco Bug IDs: CSCvh98929.Show less
1Intelbras
1Ncloud 300 Firmware
Nov 21, 2024
May 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST...Show more
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the username, password, and other details are retrieved.Show less
1Foxconn
1Ap Fc4064 T Firmware
Jun 17, 2026
May 10, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In addition, its web management page relies on the existence or values of...Show more
A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In addition, its web management page relies on the existence or values of cookies when performing security-critical operations. One can gain privileges by modifying cookies.Show less
1Redlion
2Sixnet Managed Industrial Switches Firmware
Stride Managed Ethernet Switches Firmware
Nov 21, 2024
May 9, 2018
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 and Stride-Managed Ethernet Switches running firmware Version 5.0.190....Show more
A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 and Stride-Managed Ethernet Switches running firmware Version 5.0.190. Vulnerable versions of Stride-Managed Ethernet switches and Sixnet-Managed Industrial switches use hard-coded HTTP SSL/SSH keys for secure communication. Because these keys cannot be regenerated by users, all products use the same key. The attacker could disrupt communication or compromise the system. CVSS v3 base score: 10, CVSS vector string: (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Red Lion Controls recommends updating to SLX firmware Version 5.3.174.Show less
1Fortinet
1Fortiwlc
Nov 21, 2024
May 8, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.
1Fortinet
1Fortiwlc
Nov 21, 2024
May 8, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shell.
1Rangerstudio
1Directus
Nov 21, 2024
May 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.
1Philips
4 Brilliance Ct Big Bore Firmware
Brilliance Firmware 64Brilliance Ict Firmware+1 more
Jun 17, 2026
May 4, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Philips Brilliance CT software (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bore 2.3.5 and prior) contains fixed creden...Show more
Philips Brilliance CT software (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bore 2.3.5 and prior) contains fixed credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. An attacker could compromise these credentials and gain access to the system.Show less