CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Author...Show more |
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files....Show more |
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials...Show more |
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not dis...Show more |
2Helmholz Mbconnectline2Mbnet.mini Firmware Rex 100 FirmwareJun 17, 2026 Oct 15, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. |
SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via Flash the modified firmware |
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest pr...Show more |
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials. |
1Planet 2Gs 4210 24p2s Firmware Gs 4210 24pl4c FirmwareJun 17, 2026 Sep 30, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use this community string to access the SNMPv1 service with read-write priv...Show more |
1Planet 2Gs 4210 24p2s Firmware Gs 4210 24pl4c FirmwareJun 17, 2026 Sep 30, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this creden...Show more |
1Planet 2Gs 4210 24p2s Firmware Gs 4210 24pl4c FirmwareJun 17, 2026 Sep 30, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root sh...Show more |
1Autel 1Maxicharger Ac Elite Business C50 Firmware Jun 17, 2026 Sep 28, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Autel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel Maxi...Show more |
1Doverfuelingsolutions 2Progauge Maglink Lx4 Console Firmware Progauge Maglink Lx Console FirmwareJun 17, 2026 Sep 25, 2024 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 The web application for ProGauge MAGLINK LX4 CONSOLE contains an
administrative-level user account with a password that cannot be
changed. |
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. Howev...Show more |
1Kastle 1Access Control System Firmware Jun 17, 2026 Sep 19, 2024 9.2 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker to access sensitive information. |
Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card. |
Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data. |
Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext. |
Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS comm...Show more |
Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Within an Executable.
This issue affects Cockpit Software: before v2.13. |