CWE-798
1,812 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,812)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptographic key, so anyone who knows that key and the algorithm can...Show more |
Meross MSS110 devices before 1.1.24 contain a TELNET listener providing access for an undocumented admin account with a blank password. |
1Bostonscientific 1Zoom Latitude Prm 3120 Firmware Nov 21, 2024 May 1, 2018 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Boston Scientific ZOOM LATITUDE PRM Model 3120 uses a hard-coded cryptographic key to encrypt PHI prior to having it transferred to removable media. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:...Show more |
1Watchguard 3Ap100 Firmware Ap102 FirmwareAp200 FirmwareNov 21, 2024 Apr 30, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false. |
The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a database account with privileges that can affect confidentiality, integrity, and availab...Show more |
1Momentum 1Momentum Axel 720p Firmware Nov 21, 2024 Apr 24, 2018 N/A· v4 7.4 HIGH· v3 3.3 LOW· v2 Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote attackers to view the RTSP video stream. |
1Schneider Electric 57140cpu31110 Firmware 140cpu31110c Firmware140cpu43412u Firmware+54 moreJun 17, 2026 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. |
The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers to obtain sensitive information and consequently obtain administrative...Show more |
An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with har...Show more |
The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device and uses a USB-to-UART cable to connect the device, he can use the 1234...Show more |
1Prismaindustriale 1Checkweigher Prismaweb Jun 17, 2026 Mar 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account by reading user/scripts/login_par.js. |
A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at...Show more |
A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted password parameter for the COOKIE header. |
GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to by...Show more |
GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote a...Show more |
GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authenticat...Show more |
1Ge 1Infinia Hawkeye 4 Firmware Nov 21, 2024 Mar 20, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker t...Show more |
Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contains a hard-coded cryptographic salt, "S@l+&pepper". |
1Docutracinc 1Dtisqlinstaller Jun 17, 2026 Mar 19, 2018 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain three credentials with known passwords: QDMaster, OTMaster, and sa. |
1Emc 1Data Protection Advisor Nov 21, 2024 Mar 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and various privileges. Affected accounts are: "Apollo System Test", "emc.dpa.agent.lo...Show more |