← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1Cp450 Firmware
Jun 17, 2026
Aug 1, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulat...Show more
A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273255. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Dlink
1Dir 860l Firmware
Jun 17, 2026
Jul 30, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.
1Dlink
1Dir 820lw Firmware
Jun 17, 2026
Jul 30, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.
1Totolink
1A3000ru Firmware
Jun 17, 2026
Jul 28, 2024
5.1 MEDIUM· v4
8.8 HIGH· v3
2.7 LOW· v2
A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini. The manipulation leads to use of hard-coded...Show more
A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini. The manipulation leads to use of hard-coded password. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272591. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Totolink
1A3300r Firmware
Jun 17, 2026
Jul 28, 2024
2.0 LOW· v4
4.7 MEDIUM· v3
1.0 LOW· v2
A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/shadow.sample. The manipulation leads to...Show more
A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-272569 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Syrotech
1Sy Gpon 1110 Wdont Firmware
Jun 17, 2026
Jul 26, 2024
5.2 MEDIUM· v4
4.6 MEDIUM· v3
N/A· v2
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploit this by extracting...Show more
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext WPA/ WPS credentials on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to bypass WPA/ WPS and gain access to the Wi-Fi network of the targeted system.Show less
1Perkinelmer
1Processplus
Jun 17, 2026
Jul 22, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.
1Zohocorp
1Manageengine Ddi Central
Jun 17, 2026
Jul 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.
1Tendacn
1I29 Firmware
Jun 17, 2026
Jul 16, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.
-
-
Jun 17, 2026
Jul 9, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. This is due to the use of hardcoded credentials to aut...Show more
The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to overwrite CSS, update the trial settings, purge the cache, and find attachments.Show less
-
-
Jun 17, 2026
Jul 9, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.
-
-
Jun 17, 2026
Jul 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.
1Level1
1Wbr 6013 Firmware
Jun 17, 2026
Jul 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.
1Myscada
1Mypro
Jun 17, 2026
Jul 2, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
1Kiloview
2P1 Firmware
P2 Firmware
Jun 17, 2026
Jul 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.
-
-
Jun 17, 2026
Jul 1, 2024
N/A· v4
4.0 MEDIUM· v3
N/A· v2
"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker to obtain the API key. Note that the users of the app are not directly affect...Show more
"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker to obtain the API key. Note that the users of the app are not directly affected by this vulnerability.Show less
-
-
Jun 17, 2026
Jun 27, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.
1Markoni
2Markoni D (compact) Firmware
Markoni Dh (exciter+amplifiers) Firmware
Jun 17, 2026
Jun 27, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.
-
-
Jun 17, 2026
Jun 27, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: befor...Show more
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.Show less
-
-
Jun 17, 2026
Jun 26, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive information.