← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Oct 17, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Author...Show more
A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the default password.Show less
1Cisco
1Ucs Central Software
Jun 17, 2026
Oct 16, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files....Show more
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method that is used for the backup function. An attacker could exploit this vulnerability by accessing a backup file and leveraging a static key that is used for the backup configuration feature. A successful exploit could allow an attacker with access to a backup file to learn sensitive information that is stored in full state backup files and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and the device SSL server certificate and key.Show less
1Kubernetes Sigs
1Image Builder
Jun 17, 2026
Oct 15, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials...Show more
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. The credentials are disabled at the conclusion of the image build process. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project. Because these images were vulnerable during the image build process, they are affected only if an attacker was able to reach the VM where the image build was happening and used the vulnerability to modify the image at the time the image build was occurring.Show less
1Kubernetes Sigs
1Image Builder
Jun 17, 2026
Oct 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not dis...Show more
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.Show less
2Helmholz
Mbconnectline
2Mbnet.mini Firmware
Rex 100 Firmware
Jun 17, 2026
Oct 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
-
-
Jun 17, 2026
Oct 8, 2024
7.0 HIGH· v4
N/A· v3
N/A· v2
SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via Flash the modified firmware
1Nokia
1Hit 7300 Firmware
Jun 17, 2026
Sep 30, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest pr...Show more
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.Show less
1Nokia
1Hit 7300 Firmware
Jun 17, 2026
Sep 30, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.
1Planet
2Gs 4210 24p2s Firmware
Gs 4210 24pl4c Firmware
Jun 17, 2026
Sep 30, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use this community string to access the SNMPv1 service with read-write priv...Show more
Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use this community string to access the SNMPv1 service with read-write privileges.Show less
1Planet
2Gs 4210 24p2s Firmware
Gs 4210 24pl4c Firmware
Jun 17, 2026
Sep 30, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this creden...Show more
Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.Show less
1Planet
2Gs 4210 24p2s Firmware
Gs 4210 24pl4c Firmware
Jun 17, 2026
Sep 30, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root sh...Show more
Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root shell.Show less
1Autel
1Maxicharger Ac Elite Business C50 Firmware
Jun 17, 2026
Sep 28, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Autel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel Maxi...Show more
Autel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the BLE AppAuthenRequest command handler. The handler uses hardcoded credentials as a fallback in case of an authentication request failure. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-23196Show less
1Doverfuelingsolutions
2Progauge Maglink Lx4 Console Firmware
Progauge Maglink Lx Console Firmware
Jun 17, 2026
Sep 25, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.
1Linuxfoundation
1Dragonfly
Jun 17, 2026
Sep 19, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. Howev...Show more
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. An attacker can perform any action as a user with admin privileges. This issue has been addressed in release version 2.0.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Kastle
1Access Control System Firmware
Jun 17, 2026
Sep 19, 2024
9.2 CRITICAL· v4
7.5 HIGH· v3
N/A· v2
Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker to access sensitive information.
1Govicture
1Pc420 Firmware
Jun 17, 2026
Sep 18, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.
1Govicture
1Pc420 Firmware
Jun 17, 2026
Sep 18, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.
1Govicture
1Pc420 Firmware
Jun 17, 2026
Sep 18, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.
1Dlink
1Dir X4860 Firmware
Jun 17, 2026
Sep 16, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS comm...Show more
Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can then be executed on the device.Show less
1Tnbmobil
1Cockpit
Jun 17, 2026
Sep 13, 2024
8.8 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Within an Executable. This issue affects Cockpit Software: before v2.13.