← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jun 6, 2025
9.4 CRITICAL· v4
N/A· v3
N/A· v2
A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the network, only by local users on the server.
-
-
Jun 17, 2026
May 31, 2025
5.3 MEDIUM· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects unknown code of the component Console Application. The manipulation of the argument CMCCAdmin/usera...Show more
A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects unknown code of the component Console Application. The manipulation of the argument CMCCAdmin/useradmin/CUAdmin leads to hard-coded credentials. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.Show less
-
-
Jun 17, 2026
May 30, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an unauthenticated malicious actor to log in via the web portal
-
-
Jun 17, 2026
May 30, 2025
2.7 LOW· v4
N/A· v3
N/A· v2
Project AI is a platform designed to create AI agents. Prior to the pre-beta version, a hardcoded API key was present in the source code. This issue has been patched in the pre-beta version.
-
-
Jun 17, 2026
May 30, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string in the binary responsible for running VNC. This password cannot be altered, allowing anyone with kn...Show more
The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string in the binary responsible for running VNC. This password cannot be altered, allowing anyone with knowledge of it to gain remote access to the panel. Such access could enable an attacker to operate the panel remotely, potentially putting the fire panel into a non-functional state and causing serious safety issues.Show less
1Netwrix
1Directory Manager
Jun 17, 2026
May 29, 2025
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
1Dell
1Powerstoreos
Jun 17, 2026
May 28, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials,...Show more
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges.Show less
1Perfree
1Perfreeblog
Jun 17, 2026
May 26, 2025
6.3 MEDIUM· v4
8.1 HIGH· v3
2.6 LOW· v2
A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic...Show more
A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
-
-
Jun 17, 2026
May 23, 2025
6.1 MEDIUM· v4
N/A· v3
N/A· v2
Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a local user to retrieve the SSH hash string.
-
-
Jun 17, 2026
May 23, 2025
4.7 MEDIUM· v4
N/A· v3
N/A· v2
Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure.
-
-
Jun 17, 2026
May 21, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functionality and are likely intended for debuggin...Show more
There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functionality and are likely intended for debugging during development and provides an additional attack surface.Show less
-
-
Jun 17, 2026
May 21, 2025
N/A· v4
7.7 HIGH· v3
N/A· v2
The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with the update files. There is no option for deleting or changing their passw...Show more
The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with the update files. There is no option for deleting or changing their passwords for an enduser. An attacker can use the credentials to log into the device. Authentication can be performed via SSH backdoor or likely via physical access (UART shell).Show less
1Zkteco
1Zkbio Cvsecurity
Jun 17, 2026
May 13, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the s...Show more
In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically only accessible from a local area network, and because access to the service console does not result in login access or data access in the context of the application software platform.Show less
1Microsoft
1Windows Hardware Lab Kit
Jun 17, 2026
May 13, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.
1Smarsh
1Telemessage
Jun 17, 2026
May 8, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDP...Show more
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.Show less
1Cisco
1Ios Xe
Jun 17, 2026
May 7, 2025
N/A· v4
10.0 CRITICAL· v3
N/A· v2
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an una...Show more
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected system. An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP file upload interface. A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.Show less
-
-
Jun 17, 2026
May 6, 2025
9.3 CRITICAL· v4
N/A· v3
N/A· v2
In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh server and utilize the system's components to perform OS command executions.
1Gotenna
2Gotenna
Mesh Firmware
Jun 17, 2026
May 1, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sending SMS through a goTenna server is hardcoded in the app.
1Gotenna
2Gotenna
Mesh Firmware
Jun 17, 2026
May 1, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goTenna server is hardcoded in the app.
-
-
Jun 17, 2026
Apr 29, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
CWE-798: Use of Hard-coded Credentials