← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Storage Fusion Hci
Jun 17, 2026
Jan 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or enc...Show more
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 275671.Show less
1Automaticsystems
1Soc Fl9600 Firstlane Firmware
Jul 9, 2026
Jan 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin account with astech as its hardcoded password.
1Peplink
1Balance Two Firmware
Jun 17, 2026
Dec 28, 2023
N/A· v4
6.4 MEDIUM· v3
N/A· v2
An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands a...Show more
An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root.Show less
1Fedirtsapana
1Simple Http Server Plus
Jun 17, 2026
Dec 27, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker wi...Show more
Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access to the device.Show less
1Fedirtsapana
2Simple Http Server
Simple Http Server Plus
Jun 17, 2026
Dec 27, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K (AES) encryption key. An attacker with physical...Show more
Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K (AES) encryption key. An attacker with physical access to the application's source code or binary can extract this key & use it decrypt the TLS secret.Show less
1Buffalo
1Vr S1000 Firmware
Jun 17, 2026
Dec 26, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the password of a specific product user.
1Pexip
1Virtual Meeting Rooms
Jun 17, 2026
Dec 25, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.
1Ibm
1Security Guardium Key Lifecycle Manager
Jun 17, 2026
Dec 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220.
1Paxton Access
1Net2
Jun 17, 2026
Dec 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or reverse engineer the source code to gain access to the root certificat...Show more
When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or reverse engineer the source code to gain access to the root certificate password. Using the root certificate and password they could then create their own certificates to emulate another site. Then by establishing a proxy service to emulate the site they could monitor traffic passed between the end user and the site allowing access to the data content.Show less
1Kaifa
1Webitr Attendance System
Jun 17, 2026
Dec 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to a...Show more
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including administrator’s account, to execute login account’s permissions, and obtain relevant information.Show less
1Multisuns
1Easylog Web+ Firmware
Jun 17, 2026
Dec 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.
1Csharp
1Cws Collaborative Development Platform
Jun 17, 2026
Dec 15, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific account with low privilege. An unauthenticated remote attacker can exploit this vulnerability to run...Show more
SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific account with low privilege. An unauthenticated remote attacker can exploit this vulnerability to run partial processes and obtain partial information, but can't disrupt service or obtain sensitive information.Show less
1Zoom
3Meeting Software Development Kit
Video Software Development KitZoom
Jun 17, 2026
Dec 13, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.
1Prolion
1Cryptospike
Jun 17, 2026
Dec 12, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consume the most privileged REST API endpoints via these credentials.
1Prolion
1Cryptospike
Jun 17, 2026
Dec 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via...Show more
A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.Show less
1Netscout
1Ngeniuspulse
Jun 17, 2026
Dec 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.
1Supermicro
356B12dpe 6 Firmware
B12dpt 6 FirmwareB12spe Cpu 25g Firmware+353 more
Jul 9, 2026
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02...Show more
The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands.Show less
1Enbw
1Senec Storage Box Firmware
Jun 17, 2026
Dec 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The affected devices use publicly available default credentials with administrative privileges.
1Unitronics
17Samba 3.5 Firmware
Samba 4.3 FirmwareSamba 7 Firmware+14 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable...Show more
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.Show less
1Sierrawireless
1Aleos
Jun 17, 2026
Dec 4, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the...Show more
Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server. Show less