← Back
CWE-798

1,812 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,812)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
1Oceanstor 5600 V3 Firmware
May 13, 2026
Apr 2, 2017
N/A· v4
7.5 HIGH· v3
5.4 MEDIUM· v2
Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys are used to encrypt communication data and authenticate different nodes of the devices. An attacker may obtain the hardcoded...Show more
Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys are used to encrypt communication data and authenticate different nodes of the devices. An attacker may obtain the hardcoded keys and log in to such a device through SSH.Show less
1Siklu
1Etherhaul Firmware
May 13, 2026
Mar 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's w...Show more
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.Show less
1Gotrango
5Apex Lynx Firmware
Apex Orion FirmwareGiga Lynx Firmware+2 more
May 13, 2026
Mar 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is...Show more
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet public). This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.Show less
1Trango
1A600 Firmware
May 13, 2026
Mar 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device,...Show more
Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.Show less
1Gotrango
11Apex Firmware
Apex Lynx FirmwareApex Orion Firmware+8 more
May 13, 2026
Mar 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidd...Show more
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.Show less
1Iball
1Ib Wra150n Firmware
May 13, 2026
Mar 9, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading...Show more
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.Show less
1Wepresent
1Wipg 1500 Firmware
May 13, 2026
Mar 6, 2017
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. Once the device is set to DEBUG mode, an attacker can connect to the device using the telnet proto...Show more
The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. Once the device is set to DEBUG mode, an attacker can connect to the device using the telnet protocol and log into the device with the 'abarco' hardcoded manufacturer account. This account is not documented, nor is the DEBUG feature or the use of telnetd on port tcp/5885.Show less
1Rapid7
1Nexpose
May 13, 2026
Mar 2, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not modifiable by the user. The keystore provides storage for saved scan c...Show more
The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not modifiable by the user. The keystore provides storage for saved scan credentials in an otherwise secure location on disk.Show less
1Veritas
2Netbackup
Netbackup Appliance
May 13, 2026
Mar 2, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username and password.
1Binom3
1Universal Multifunctional Electric Power Quality Meter Firmware
May 13, 2026
Feb 13, 2017
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users do not have any option to change their own passwords.
1Siemens
1Sicam Pas/pqs
May 13, 2026
Feb 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Attackers might gain privileged access to the database over Port 2638/TCP.
1Lynxspring
1Jenesys Bas Bridge
May 13, 2026
Feb 13, 2017
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication.
1Schneider Electric
1Powerlogic Pm8ecc Firmware
May 13, 2026
Feb 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the device.
1Ibm
1Dashdb Local
May 13, 2026
Feb 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.
1Netapp
1Oncommand Insight
May 13, 2026
Feb 2, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account.
1Fortinet
1Fortiwlc
May 13, 2026
Feb 1, 2017
N/A· v4
9.1 CRITICAL· v3
9.4 HIGH· v2
The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.
1Dlink
1Dwr 932b Firmware
May 13, 2026
Jan 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.
1Dlink
1Dwr 932b Firmware
May 13, 2026
Jan 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.
1Dlink
1Dgs 1100 Firmware
May 6, 2026
Jan 9, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session.
1Trane
1Comfortlink Ii Firmware
May 6, 2026
Jan 6, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.