CWE-798
1,812 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,812)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Huawei 1Oceanstor 5600 V3 Firmware May 13, 2026 Apr 2, 2017 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys are used to encrypt communication data and authenticate different nodes of the devices. An attacker may obtain the hardcoded...Show more |
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's w...Show more |
1Gotrango 5Apex Lynx Firmware Apex Orion FirmwareGiga Lynx Firmware+2 moreMay 13, 2026 Mar 30, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is...Show more |
Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device,...Show more |
1Gotrango 11Apex Firmware Apex Lynx FirmwareApex Orion Firmware+8 moreMay 13, 2026 Mar 30, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidd...Show more |
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading...Show more |
The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. Once the device is set to DEBUG mode, an attacker can connect to the device using the telnet proto...Show more |
The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not modifiable by the user. The keystore provides storage for saved scan c...Show more |
1Veritas 2Netbackup Netbackup ApplianceMay 13, 2026 Mar 2, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username and password. |
1Binom3 1Universal Multifunctional Electric Power Quality Meter Firmware May 13, 2026 Feb 13, 2017 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users do not have any option to change their own passwords. |
An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Attackers might gain privileged access to the database over Port 2638/TCP. |
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication. |
1Schneider Electric 1Powerlogic Pm8ecc Firmware May 13, 2026 Feb 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the device. |
IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database. |
The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account. |
The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell. |
An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607. |
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234. |
D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session. |
1Trane 1Comfortlink Ii Firmware May 6, 2026 Jan 6, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system. |