CWE-798
1,812 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,812)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-digit code, displayed on-screen - ensuring only those who can view it...Show more |
A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical attacker to access an...Show more |
1Schneider Electric 1U.motion Builder May 13, 2026 Sep 26, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can use this information...Show more |
1Schneider Electric 1U.motion Builder May 13, 2026 Sep 26, 2017 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains a hard-coded valid session. An attacker can use that session ID as par...Show more |
Multiple hardcoded credentials in Xsuite 2.x. |
1Tecnovision 1Dlx Spot Player4 May 13, 2026 Sep 21, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A hard-coded password of tecn0visi0n for the dlxuser account in TecnoVISION DLX Spot Player4 (all known versions) allows remote attackers to log in via SSH and escalate privileges to root access with the same credentials...Show more |
1Mirion Technologies 7Dmc 3000 Firmware Drm 1/2 FirmwareIpam Transmitter F/dmc 2000 Firmware+4 moreMay 13, 2026 Sep 20, 2017 N/A· v4 5.0 MEDIUM· v3 5.4 MEDIUM· v2 A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (incl...Show more |
1Twsz 1Wifi Repeater Firmware May 13, 2026 Sep 20, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root") and can: 1. Read the entire file system; 2. Write to the f...Show more |
1Twsz 1Wifi Repeater Firmware May 13, 2026 Sep 20, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root"). The attacker can make a user that is connected to the rep...Show more |
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers to bypass an intended protection mechanism and consequently conduct PHP...Show more |
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/run/hostapd* permissions. |
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0644 /var/etc/shadow (aka the /etc/shadow symlink target) permissions. |
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices use the same hardcoded /etc/stunnel.key private key across different customers' installations, wh...Show more |
D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices have a hardcoded password of wrgac25_dlink.2013gui_dir850l for the Alphanetworks account upon device reset, which allows remote attackers to obtain root a...Show more |
Axesstel MU553S MU55XS-V1.14 devices have a default password of admin for the admin account. |
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver https service with the tech account and an empty password, which allows remote a...Show more |
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanent-enable WAN SSH logins to the remotessh account with the 5SaP9I26 password, whic...Show more |
Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015. |
1Westermo 4Mrd 305 Din Firmware Mrd 315 Din FirmwareMrd 355 Din Firmware+1 moreMay 13, 2026 Aug 25, 2017 N/A· v4 5.3 MEDIUM· v3 2.1 LOW· v2 A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded credentials, which could allow fo...Show more |
1Westermo 4Mrd 305 Din Firmware Mrd 315 Din FirmwareMrd 355 Din Firmware+1 moreMay 13, 2026 Aug 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded private cryptographic keys...Show more |