← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Smartsitecms
1Smartsitecms
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
admin.php in SmartSiteCMS 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the userName cookie.
1Cisco
6Unified Ip Phone Firmware 7906g
Unified Ip Phone Firmware 7911gUnified Ip Phone Firmware 7941g+3 more
Apr 23, 2026
Feb 22, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.
1Cisco
1Unified Wireless Ip Phone 7920 Firmware
Apr 16, 2026
Nov 24, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded ("fixed") public and private SNMP community strings that cannot be changed, which allows remote attackers to obtain sensitive information.
1Utstarcom
1F1000 Wi Fi Firmware
Apr 16, 2026
Nov 21, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SNMP daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has hard-coded public credentials that cannot be changed, which allows attackers to obtain sensitive information.
1Arkeia
1Network Backup
Apr 16, 2026
Feb 21, 2005
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.
1Microsoft
1Exchange Server
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.