← Back
CWE-798

1,812 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,812)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Marel
22A320 Firmware
A325 FirmwareA371 Firmware+19 more
May 13, 2026
Jun 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC...Show more
A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C; M3210 terminal associated with the same systems as the M3000 terminal identified above; M3000 desktop software associated with the same systems as the M3000 terminal identified above; MAC4 controller associated with the same systems as the M3000 terminal identified above; SensorX23 X-ray machine; SensorX25 X-ray machine; and MWS2 weighing system. The end user does not have the ability to change system passwords.Show less
1Foscam
1C1 Webcam Firmware
May 13, 2026
Jun 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked...Show more
Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked by an intermediate device.Show less
1Nagios
1Nagios
May 13, 2026
Jun 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.
1Phoenixbroadband
1Poweragent Sc3 Bms Firmware
May 13, 2026
Jun 2, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A Use of Hard-Coded Password issue was discovered in Phoenix Broadband PowerAgent SC3 BMS, all versions prior to v6.87. Use of a hard-coded password may allow unauthorized access to the device.
1F5
9Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Application Acceleration Manager+6 more
May 13, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which could be used to remotely log into the BIG-IP system. The impacted administ...Show more
In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which could be used to remotely log into the BIG-IP system. The impacted administrative account is the Azure instance administrative user that was created at deployment. The root and admin accounts are not vulnerable. An attacker may be able to remotely access the BIG-IP host via SSH.Show less
1Mimosa
2Backhaul Radios
Client Radios
May 13, 2026
May 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A hard-coded credentials issue was discovered on Mimosa Client Radios before 2.2.3, Mimosa Backhaul Radios before 2.2.3, and Mimosa Access Points before 2.2.3. These devices run Mosquitto, a lightweight message broker, t...Show more
A hard-coded credentials issue was discovered on Mimosa Client Radios before 2.2.3, Mimosa Backhaul Radios before 2.2.3, and Mimosa Access Points before 2.2.3. These devices run Mosquitto, a lightweight message broker, to send information between devices. By using the vendor's hard-coded credentials to connect to the broker on any device (whether it be an AP, Client, or Backhaul model), an attacker can view all the messages being sent between the devices. If an attacker connects to an AP, the AP will leak information about any clients connected to it, including the serial numbers, which can be used to remotely factory reset the clients via a page in their web interface.Show less
1Dahuasecurity
15Dh Hcvr4xxx Firmware
Dh Hcvr5xxx FirmwareDh Ipc Hdbw13a0sn Firmware+12 more
May 13, 2026
May 6, 2017
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-...Show more
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password.Show less
2Hyundai
Hyundaiusa
2Blue Link
Blue Link
Apr 6, 2026
Apr 26, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Use of Hard-Coded Cryptographic Key issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. The application uses a hard-coded decryption password to protect sensitive user information.
1Wificam
1Wireless Ip Camera (p2p) Firmware
May 13, 2026
Apr 25, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET.
1D Link
1Dvg N5402sp Firmware
May 13, 2026
Apr 24, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative ac...Show more
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative access.Show less
1Tp Link
1Tl Sg108e Firmware
May 13, 2026
Apr 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On the TP-Link TL-SG108E 1.0, there is a hard-coded ciphering key (a long string beginning with Ei2HNryt). This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
1Exagrid
8Ex10000e Firmware
Ex13000e FirmwareEx21000e Firmware+5 more
May 13, 2026
Apr 21, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain a...Show more
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.Show less
1Intellinet Network
1Nfc 30ir Firmware
May 13, 2026
Apr 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.
1Foscam
12C1
C1 LiteC2+9 more
May 13, 2026
Apr 10, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key f...Show more
Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.Show less
1Ibaby
1M3s Baby Monitor Firmware
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
iBaby M3S has a password of admin for the backdoor admin account.
1Lens Laboratories
1Peek A View Firmware
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Lens Peek-a-View has a password of 2601hx for the backdoor admin account, a password of user for the backdoor user account, and a password of guest for the backdoor guest account.
1Philips
1In.sight B120\37
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a password of merlin for the backdoor mg3500 account, a password of M100-4674448 fo...Show more
Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a password of merlin for the backdoor mg3500 account, a password of M100-4674448 for the backdoor user account, and a password of M100-4674448 for the backdoor admin account.Show less
1Gynoii
3Gcw 1010
Gcw 1020Gpw 1025
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Gynoii has a password of guest for the backdoor guest account and a password of 12345 for the backdoor admin account.
1Dragonwavex
1Horizon Wireless Radio Firmware
May 13, 2026
Apr 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in t...Show more
DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions including 1.4.8.Show less
1Schneider Electric
2Modicon Tm221ce16r Firmware
Somachine
May 29, 2026
Apr 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening a...Show more
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected project file, by prompting the user for a password. This XML file is AES-CBC encrypted; however, the key used for encryption (SoMachineBasicSoMachineBasicSoMa) cannot be changed. After decrypting the XML file with this key, the user password can be found in the decrypted data. After reading the user password, the project can be opened and modified with the Schneider product.Show less