← Back
CWE-798

1,812 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,812)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netgear
3Arlo Base Station Firmware
Arlo Q Camera FirmwareArlo Q Plus Camera Firmware
May 6, 2026
Jan 4, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, whic...Show more
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access after a factory reset or in a factory configuration.Show less
1Sap
1Download Manager
May 6, 2026
Dec 14, 2016
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging...Show more
SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of a hardcoded key in the program code and a computer BIOS serial number, aka SAP Security Note 2282338.Show less
3Canonical
DjangoprojectFedoraproject
3Django
FedoraUbuntu Linux
May 6, 2026
Dec 9, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attack...Show more
Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.Show less
2Barclamp Trove Project
Crowbar Openstack Project
2Barclamp Trove
Crowbar Openstack
May 6, 2026
Dec 9, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for...Show more
The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.Show less
1Ibm
1Bigfix Remote Control
May 6, 2026
Nov 30, 2016
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.
1Fortinet
1Fortiwlc
May 6, 2026
Oct 5, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remote attackers to read or write to arbitrary files via unspecifi...Show more
The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remote attackers to read or write to arbitrary files via unspecified vectors.Show less
1Dexis
1Imaging Suite
May 6, 2026
Sep 24, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this password in a DEXIS_DATA SQL Server session.
1Dentsply Sirona
1Cdr Dicom
May 6, 2026
Sep 21, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain administrative access by leveraging knowledge of these passwords.
1Aver
1Eh6108h+ Firmware
May 6, 2026
Sep 19, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishing a TELNET session.
1Nuuo
2Nvrmini 2
Nvrsolo
May 6, 2026
Aug 31, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.
1Vmware
1Photon Os
May 6, 2026
Aug 31, 2016
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
1Rockwellautomation
61766 L32awa
1766 L32awaa1766 L32bwa+3 more
Jun 3, 2026
Aug 24, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote attackers to load arbi...Show more
Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote attackers to load arbitrary firmware updates by leveraging knowledge of this community.Show less
1Zmodo
2Zp Ibh 13w
Zp Ne 14 S
May 6, 2026
Aug 24, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET session.
1Ge
1Multilink Firmware
May 6, 2026
Jun 9, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote att...Show more
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify configuration settings via the web interface.Show less
1Schneider Electric
5Etg3000 Factorycast Hmi Gateway Firmware
Tsxetg3000Tsxetg3010+2 more
May 6, 2026
Jan 27, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.
1Emerson
1Deltav
May 6, 2026
May 22, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that...Show more
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.Show less
1Moxa
1Edr G903 Firmware
Apr 29, 2026
Feb 15, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access via unknown vectors.
1Carlosgavazzi
2Eos Box Photovoltaic Monitoring System
Eos Box Photovoltaic Monitoring System Firmware
Apr 29, 2026
Dec 23, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into the device with administrative privileges. This could allow the attacker...Show more
The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.Show less
2Redhat
Theforeman
2Enterprise Linux Server
Katello
Apr 29, 2026
Aug 25, 2012
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers t...Show more
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.Show less
1Siemens
2Simatic Pcs 7
Simatic Wincc
Apr 29, 2026
Jul 22, 2010
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a differe...Show more
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.Show less