← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dahuasecurity
15Dh Hcvr4xxx Firmware
Dh Hcvr5xxx FirmwareDh Ipc Hdbw13a0sn Firmware+12 more
May 13, 2026
May 6, 2017
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-...Show more
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password.Show less
2Hyundai
Hyundaiusa
2Blue Link
Blue Link
Apr 6, 2026
Apr 26, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Use of Hard-Coded Cryptographic Key issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. The application uses a hard-coded decryption password to protect sensitive user information.
1Wificam
1Wireless Ip Camera (p2p) Firmware
May 13, 2026
Apr 25, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET.
1D Link
1Dvg N5402sp Firmware
May 13, 2026
Apr 24, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative ac...Show more
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative access.Show less
1Tp Link
1Tl Sg108e Firmware
May 13, 2026
Apr 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On the TP-Link TL-SG108E 1.0, there is a hard-coded ciphering key (a long string beginning with Ei2HNryt). This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
1Exagrid
8Ex10000e Firmware
Ex13000e FirmwareEx21000e Firmware+5 more
May 13, 2026
Apr 21, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain a...Show more
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.Show less
1Intellinet Network
1Nfc 30ir Firmware
May 13, 2026
Apr 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.
1Foscam
12C1
C1 LiteC2+9 more
May 13, 2026
Apr 10, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key f...Show more
Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.Show less
1Ibaby
1M3s Baby Monitor Firmware
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
iBaby M3S has a password of admin for the backdoor admin account.
1Lens Laboratories
1Peek A View Firmware
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Lens Peek-a-View has a password of 2601hx for the backdoor admin account, a password of user for the backdoor user account, and a password of guest for the backdoor guest account.
1Philips
1In.sight B120\37
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a password of merlin for the backdoor mg3500 account, a password of M100-4674448 fo...Show more
Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a password of merlin for the backdoor mg3500 account, a password of M100-4674448 for the backdoor user account, and a password of M100-4674448 for the backdoor admin account.Show less
1Gynoii
3Gcw 1010
Gcw 1020Gpw 1025
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Gynoii has a password of guest for the backdoor guest account and a password of 12345 for the backdoor admin account.
1Dragonwavex
1Horizon Wireless Radio Firmware
May 13, 2026
Apr 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in t...Show more
DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions including 1.4.8.Show less
1Schneider Electric
2Modicon Tm221ce16r Firmware
Somachine
May 29, 2026
Apr 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening a...Show more
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected project file, by prompting the user for a password. This XML file is AES-CBC encrypted; however, the key used for encryption (SoMachineBasicSoMachineBasicSoMa) cannot be changed. After decrypting the XML file with this key, the user password can be found in the decrypted data. After reading the user password, the project can be opened and modified with the Schneider product.Show less
1Huawei
1Oceanstor 5600 V3 Firmware
May 13, 2026
Apr 2, 2017
N/A· v4
7.5 HIGH· v3
5.4 MEDIUM· v2
Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys are used to encrypt communication data and authenticate different nodes of the devices. An attacker may obtain the hardcoded...Show more
Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys are used to encrypt communication data and authenticate different nodes of the devices. An attacker may obtain the hardcoded keys and log in to such a device through SSH.Show less
1Siklu
1Etherhaul Firmware
May 13, 2026
Mar 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's w...Show more
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.Show less
1Gotrango
5Apex Lynx Firmware
Apex Orion FirmwareGiga Lynx Firmware+2 more
May 13, 2026
Mar 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is...Show more
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet public). This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.Show less
1Trango
1A600 Firmware
May 13, 2026
Mar 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device,...Show more
Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.Show less
1Gotrango
11Apex Firmware
Apex Lynx FirmwareApex Orion Firmware+8 more
May 13, 2026
Mar 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidd...Show more
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.Show less
1Iball
1Ib Wra150n Firmware
May 13, 2026
Mar 9, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading...Show more
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.Show less