CWE-798
1,812 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,812)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardcoded password of support for the support account, and a hardcoded password of user for the user acco...Show more |
1Ibm 1Tealeaf Customer Experience Nov 21, 2024 Jan 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 contains hard-coded credentials. A remote attacker could exploit this vulnerability to gain access to the system. IBM X-Force ID: 123740. |
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password,...Show more |
1Barni 1Master Ip Camera01 Firmware Jun 17, 2026 Jan 16, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server. |
1Barni 1Master Ip Camera01 Firmware Jun 17, 2026 Jan 16, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account. |
1Trendnet 1Tew 823dru Firmware Nov 21, 2024 Jan 5, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account, which makes it easier for remote attackers to obtain access via an FTP session. |
1Zivif 1Pr115 204 P Rs Firmware May 13, 2026 Dec 19, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Zivif PR115-204-P-RS V2.3.4.2103 web cameras contain a hard-coded cat1029 password for the root user. The SONIX operating system's setup renders this password unchangeable and it can be used to access the device via a TE...Show more |
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all devices. A remote attacker can take complete control of a device using default adm...Show more |
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset page. An unauthenticated, remote attacker can exploit this vulnerability b...Show more |
The SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with the knowledge of the password might potentially disable the SMI-S serv...Show more |
1Huawei 1Fusionsphere Openstack May 13, 2026 Nov 22, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 FusionSphere OpenStack V100R006C00 has an information exposure vulnerability. The software uses hard-coded cryptographic key to encrypt messages between certain components, which significantly increases the possibility t...Show more |
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing FRP partition using reference FRP unlock, authentication method can be compromised for static...Show more |
1Cisco 2Umbrella Insights Virtual Appliance Umbrella Virtual ApplianceJun 22, 2026 Nov 16, 2017 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected virtual appliance with root privileges. The vulnerability is due to th...Show more |
1Korenix 9Jetnet5018g Firmware Jetnet5310g FirmwareJetnet5428g 2g 2fx Firmware+6 moreMay 13, 2026 Nov 1, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24...Show more |
1Korenix 9Jetnet5018g Firmware Jetnet5310g FirmwareJetnet5428g 2g 2fx Firmware+6 moreMay 13, 2026 Nov 1, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet57...Show more |
EMC AppSync Server prior to 3.5.0.1 contains database accounts with hardcoded passwords that could potentially be exploited by malicious users to compromise the affected system. |
In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of s...Show more |
D-Link DGS-1500 Ax devices before 2.51B021 have a hardcoded password, which allows remote attackers to obtain shell access. |
1Cisco 1Advanced Malware Protection May 13, 2026 Oct 22, 2017 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in t...Show more |
The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior...Show more |