← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wepresent
1Wipg 1500 Firmware
May 13, 2026
Mar 6, 2017
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. Once the device is set to DEBUG mode, an attacker can connect to the device using the telnet proto...Show more
The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. Once the device is set to DEBUG mode, an attacker can connect to the device using the telnet protocol and log into the device with the 'abarco' hardcoded manufacturer account. This account is not documented, nor is the DEBUG feature or the use of telnetd on port tcp/5885.Show less
1Rapid7
1Nexpose
May 13, 2026
Mar 2, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not modifiable by the user. The keystore provides storage for saved scan c...Show more
The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not modifiable by the user. The keystore provides storage for saved scan credentials in an otherwise secure location on disk.Show less
1Veritas
2Netbackup
Netbackup Appliance
May 13, 2026
Mar 2, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username and password.
1Binom3
1Universal Multifunctional Electric Power Quality Meter Firmware
May 13, 2026
Feb 13, 2017
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users do not have any option to change their own passwords.
1Siemens
1Sicam Pas/pqs
May 13, 2026
Feb 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Attackers might gain privileged access to the database over Port 2638/TCP.
1Lynxspring
1Jenesys Bas Bridge
May 13, 2026
Feb 13, 2017
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication.
1Schneider Electric
1Powerlogic Pm8ecc Firmware
May 13, 2026
Feb 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the device.
1Ibm
1Dashdb Local
May 13, 2026
Feb 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.
1Netapp
1Oncommand Insight
May 13, 2026
Feb 2, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account.
1Fortinet
1Fortiwlc
May 13, 2026
Feb 1, 2017
N/A· v4
9.1 CRITICAL· v3
9.4 HIGH· v2
The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.
1Dlink
1Dwr 932b Firmware
May 13, 2026
Jan 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.
1Dlink
1Dwr 932b Firmware
May 13, 2026
Jan 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.
1Dlink
1Dgs 1100 Firmware
May 6, 2026
Jan 9, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session.
1Trane
1Comfortlink Ii Firmware
May 6, 2026
Jan 6, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.
1Netgear
3Arlo Base Station Firmware
Arlo Q Camera FirmwareArlo Q Plus Camera Firmware
May 6, 2026
Jan 4, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, whic...Show more
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access after a factory reset or in a factory configuration.Show less
1Sap
1Download Manager
May 6, 2026
Dec 14, 2016
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging...Show more
SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of a hardcoded key in the program code and a computer BIOS serial number, aka SAP Security Note 2282338.Show less
3Canonical
DjangoprojectFedoraproject
3Django
FedoraUbuntu Linux
May 6, 2026
Dec 9, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attack...Show more
Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.Show less
2Barclamp Trove Project
Crowbar Openstack Project
2Barclamp Trove
Crowbar Openstack
May 6, 2026
Dec 9, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for...Show more
The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.Show less
1Ibm
1Bigfix Remote Control
May 6, 2026
Nov 30, 2016
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.
1Fortinet
1Fortiwlc
May 6, 2026
Oct 5, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remote attackers to read or write to arbitrary files via unspecifi...Show more
The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remote attackers to read or write to arbitrary files via unspecified vectors.Show less