← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synaptics
1Fingerprint Driver
Jun 17, 2026
Jan 27, 2024
N/A· v4
5.2 MEDIUM· v3
N/A· v2
Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This...Show more
Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This may allow an attacker, who has physical access to the sensor, to enroll a fingerprint into the template database.Show less
1Ibm
1Merge Efilm Workstation
Jun 17, 2026
Jan 26, 2024
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerability to achieve information disclosure or remote code execution.
1Spooncast
1Spoon
Jun 17, 2026
Jan 24, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be us...Show more
Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service.Show less
1Hitron
1Lguvr 16h Firmware
Jun 17, 2026
Jan 23, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
1Hitron
1Lguvr 8h Firmware
Jun 17, 2026
Jan 23, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
1Hitron
1Lguvr 4h Firmware
Jun 17, 2026
Jan 23, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
1Hitron
1Hvr 16781 Firmware
Jun 17, 2026
Jan 23, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
1Hitron
1Hvr 8781 Firmware
Jun 17, 2026
Jan 23, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
1Hitron
1Hvr 4781 Firmware
Jun 17, 2026
Jan 23, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
1Ubeeinteractive
1Ddw365 Firmware
Jun 17, 2026
Jan 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a bea...Show more
Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by using the first six characters of the SSID and the last six of the BSSID, decrementing the last digit.Show less
1Openlibraryfoundation
1Mod Data Export Spring
Jul 14, 2026
Jan 19, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on,...Show more
Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate fees/fines.Show less
1Openlibraryfoundation
1Mod Remote Storage
Jul 14, 2026
Jan 19, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-t...Show more
Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types.Show less
1Evershop
1Evershop
Jun 17, 2026
Jan 13, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC secret poses a risk because attackers can use the pr...Show more
An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC secret poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.Show less
1Skoda Auto
1Superb 3 Firmware
Jun 17, 2026
Jan 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulnerability discovered on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.
1Hongdian
1H8951 4g Esp Firmware
Jun 17, 2026
Jan 12, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.
1Hongdian
1H8951 4g Esp Firmware
Jun 17, 2026
Jan 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Root user password is hardcoded into the device and cannot be changed in the user interface.
1Flient
1Smart Lock Advanced Firmware
Jun 17, 2026
Jan 11, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain design choices, an attacker can unlock the Flient Smart Door Lock by r...Show more
Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain design choices, an attacker can unlock the Flient Smart Door Lock by replacing the fingerprint that is stored on the scanner.Show less
1Bosch
1Nexo Os
Jun 17, 2026
Jan 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.
1Bosch
1Nexo Os
Jun 17, 2026
Jan 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.
1Appwrite
1Command Line Interface
Jun 17, 2026
Jan 9, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those cr...Show more
In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.Show less