CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
admin.php in SmartSiteCMS 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the userName cookie. |
1Cisco 6Unified Ip Phone Firmware 7906g Unified Ip Phone Firmware 7911gUnified Ip Phone Firmware 7941g+3 moreApr 23, 2026 Feb 22, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device. |
1Cisco 1Unified Wireless Ip Phone 7920 Firmware Apr 16, 2026 Nov 24, 2005 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded ("fixed") public and private SNMP community strings that cannot be changed, which allows remote attackers to obtain sensitive information. |
1Utstarcom 1F1000 Wi Fi Firmware Apr 16, 2026 Nov 21, 2005 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The SNMP daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has hard-coded public credentials that cannot be changed, which allows attackers to obtain sensitive information. |
Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands. |
The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability. |