CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Totolink 1Cp450 Firmware Jun 17, 2026 Aug 1, 2024 9.3 CRITICAL· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulat...Show more |
In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands. |
D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands. |
1Totolink 1A3000ru Firmware Jun 17, 2026 Jul 28, 2024 5.1 MEDIUM· v4 8.8 HIGH· v3 2.7 LOW· v2 A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini. The manipulation leads to use of hard-coded...Show more |
A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/shadow.sample. The manipulation leads to...Show more |
1Syrotech 1Sy Gpon 1110 Wdont Firmware Jun 17, 2026 Jul 26, 2024 5.2 MEDIUM· v4 4.6 MEDIUM· v3 N/A· v2 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploit this by extracting...Show more |
1Perkinelmer 1Processplus Jun 17, 2026 Jul 22, 2024 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0. |
1Zohocorp 1Manageengine Ddi Central Jun 17, 2026 Jul 17, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys. |
Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root. |
The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. This is due to the use of hardcoded credentials to aut...Show more |
An high privileged remote attacker can enable telnet access that accepts hardcoded credentials. |
An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.
|
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution. |
mySCADA myPRO
uses a hard-coded password which could allow an attacker to remotely execute code on the affected device. |
Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access. |
"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker to obtain the API key. Note that the users of the app are not directly affect...Show more |
luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials. |
1Markoni 2Markoni D (compact) Firmware Markoni Dh (exciter+amplifiers) FirmwareJun 17, 2026 Jun 27, 2024 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials. |
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: befor...Show more |
A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive information. |