← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dexis
1Imaging Suite
May 6, 2026
Sep 24, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this password in a DEXIS_DATA SQL Server session.
1Dentsply Sirona
1Cdr Dicom
May 6, 2026
Sep 21, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain administrative access by leveraging knowledge of these passwords.
1Aver
1Eh6108h+ Firmware
May 6, 2026
Sep 19, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishing a TELNET session.
1Nuuo
2Nvrmini 2
Nvrsolo
May 6, 2026
Aug 31, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.
1Vmware
1Photon Os
May 6, 2026
Aug 31, 2016
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
1Rockwellautomation
61766 L32awa
1766 L32awaa1766 L32bwa+3 more
Jun 3, 2026
Aug 24, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote attackers to load arbi...Show more
Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote attackers to load arbitrary firmware updates by leveraging knowledge of this community.Show less
1Zmodo
2Zp Ibh 13w
Zp Ne 14 S
May 6, 2026
Aug 24, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET session.
1Ge
1Multilink Firmware
May 6, 2026
Jun 9, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote att...Show more
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify configuration settings via the web interface.Show less
1Schneider Electric
5Etg3000 Factorycast Hmi Gateway Firmware
Tsxetg3000Tsxetg3010+2 more
May 6, 2026
Jan 27, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.
1Emerson
1Deltav
May 6, 2026
May 22, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that...Show more
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.Show less
1Moxa
1Edr G903 Firmware
Apr 29, 2026
Feb 15, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access via unknown vectors.
1Carlosgavazzi
2Eos Box Photovoltaic Monitoring System
Eos Box Photovoltaic Monitoring System Firmware
Apr 29, 2026
Dec 23, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into the device with administrative privileges. This could allow the attacker...Show more
The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.Show less
2Redhat
Theforeman
2Enterprise Linux Server
Katello
Apr 29, 2026
Aug 25, 2012
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers t...Show more
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.Show less
1Siemens
2Simatic Pcs 7
Simatic Wincc
Apr 29, 2026
Jul 22, 2010
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a differe...Show more
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.Show less
1Debian
1Pyftpd
Apr 29, 2026
Jun 16, 2010
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
auth_db_config.py in Pyftpd 0.8.4 contains hard-coded usernames and passwords for the (1) test, (2) user, and (3) roxon accounts, which allows remote attackers to read arbitrary files from the FTP server.
1Linksys
1Wap54g Firmware
Apr 29, 2026
Jun 10, 2010
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the...Show more
Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi.Show less
1Redhat
1Satellite
Apr 23, 2026
Aug 14, 2008
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the server and obtain sensitive information about user accounts and entitlemen...Show more
manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the server and obtain sensitive information about user accounts and entitlements.Show less
1Emc
1Diskxtender
Apr 23, 2026
Apr 14, 2008
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface.
1Zyxel
1Zywall 1050 Firmware
Apr 23, 2026
Mar 25, 2008
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.
1Utimaco
1Safeguard
Apr 23, 2026
Mar 7, 2007
N/A· v4
7.8 HIGH· v3
4.1 MEDIUM· v2
The centralized management feature for Utimaco Safeguard stores hard-coded cryptographic keys in executable programs for encrypted configuration files, which allows attackers to recover the keys from the configuration fi...Show more
The centralized management feature for Utimaco Safeguard stores hard-coded cryptographic keys in executable programs for encrypted configuration files, which allows attackers to recover the keys from the configuration files and decrypt the disk drive.Show less