← Back
CWE-798

1,812 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,812)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Debian
1Pyftpd
Apr 29, 2026
Jun 16, 2010
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
auth_db_config.py in Pyftpd 0.8.4 contains hard-coded usernames and passwords for the (1) test, (2) user, and (3) roxon accounts, which allows remote attackers to read arbitrary files from the FTP server.
1Linksys
1Wap54g Firmware
Apr 29, 2026
Jun 10, 2010
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the...Show more
Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi.Show less
1Redhat
1Satellite
Apr 23, 2026
Aug 14, 2008
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the server and obtain sensitive information about user accounts and entitlemen...Show more
manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the server and obtain sensitive information about user accounts and entitlements.Show less
1Emc
1Diskxtender
Apr 23, 2026
Apr 14, 2008
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface.
1Zyxel
1Zywall 1050 Firmware
Apr 23, 2026
Mar 25, 2008
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.
1Utimaco
1Safeguard
Apr 23, 2026
Mar 7, 2007
N/A· v4
7.8 HIGH· v3
4.1 MEDIUM· v2
The centralized management feature for Utimaco Safeguard stores hard-coded cryptographic keys in executable programs for encrypted configuration files, which allows attackers to recover the keys from the configuration fi...Show more
The centralized management feature for Utimaco Safeguard stores hard-coded cryptographic keys in executable programs for encrypted configuration files, which allows attackers to recover the keys from the configuration files and decrypt the disk drive.Show less
1Smartsitecms
1Smartsitecms
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
admin.php in SmartSiteCMS 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the userName cookie.
1Cisco
6Unified Ip Phone Firmware 7906g
Unified Ip Phone Firmware 7911gUnified Ip Phone Firmware 7941g+3 more
Apr 23, 2026
Feb 22, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.
1Cisco
1Unified Wireless Ip Phone 7920 Firmware
Apr 16, 2026
Nov 24, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded ("fixed") public and private SNMP community strings that cannot be changed, which allows remote attackers to obtain sensitive information.
1Utstarcom
1F1000 Wi Fi Firmware
Apr 16, 2026
Nov 21, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SNMP daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has hard-coded public credentials that cannot be changed, which allows attackers to obtain sensitive information.
1Arkeia
1Network Backup
Apr 16, 2026
Feb 21, 2005
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.
1Microsoft
1Exchange Server
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.