← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Juplink
1Rx4 1500 Firmware
Jun 17, 2026
Sep 18, 2023
N/A· v4
9.8 CRITICAL· v3
5.8 MEDIUM· v2
Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user.
1Peppermint
1Peppermint
Jun 17, 2026
Sep 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie.
1Vaxilu
1X Ui
Jul 9, 2026
Sep 18, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
1Netis Systems
1Wf2409e Firmware
Jun 17, 2026
Sep 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component.
1I Doit
1I Doit
Jun 17, 2026
Sep 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthe...Show more
i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain Administrator privileges, resulting in them being able to perform arbitrary system operations or cause a Denial of Service (DoS).Show less
1Fortinet
1Fortitester
Jun 17, 2026
Sep 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who managed to get a shell on the device to access the database via shell commands.
1Xpand It
1Write Back Manager
Jun 17, 2026
Sep 12, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.
1Resortdata
1Internet Reservation Module Next Generation
Jun 17, 2026
Sep 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this...Show more
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.Show less
1Resortdata
1Internet Reservation Module Next Generation
Jun 17, 2026
Sep 7, 2023
N/A· v4
7.7 HIGH· v3
N/A· v2
The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these ser...Show more
The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.Show less
1Resortdata
1Internet Reservation Module Next Generation
Jun 17, 2026
Sep 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL fi...Show more
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an attacker generate the daily password and connect to application customers. Given that this is an administrative account, anyone logging into a customer deployment has full, unrestricted access to the application.Show less
1Tp Link
2Archer C50 V3 Firmware
Archer C55 Firmware
Jun 17, 2026
Sep 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use hard-coded credentials to login to the affected device, which may allow a network-...Show more
Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use hard-coded credentials to login to the affected device, which may allow a network-adjacent unauthenticated attacker to execute an arbitrary OS command.Show less
1Superstorefinder
1Super Store Finder
Jun 17, 2026
Sep 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.
1Moxa
1Mxsecurity
Jun 17, 2026
Sep 2, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attribut...Show more
A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate man-in-the-middle attacks and enable the decryption of SSH traffic.Show less
1Selinc
1Sel 5037 Sel Grid Configurator
Jun 17, 2026
Aug 31, 2023
N/A· v4
8.4 HIGH· v3
N/A· v2
Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Windows allows Authentication Bypass. See Instruction Manual Appendix A and Appendix E dated 2023061...Show more
Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Windows allows Authentication Bypass. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue affects SEL-5037 SEL Grid Configurator: before 4.5.0.20. Show less
1Motorola
1Mbts Base Radio Firmware
Jun 17, 2026
Aug 29, 2023
N/A· v4
8.4 HIGH· v3
N/A· v2
Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoo...Show more
Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.Show less
1Motorola
1Mbts Site Controller Firmware
Jun 17, 2026
Aug 29, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-cod...Show more
Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.Show less
1Myspotcam
1Fhd 2 Firmware
Jun 17, 2026
Aug 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service...Show more
SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service. Show less
1Myspotcam
1Fhd 2 Firmware
Jun 17, 2026
Aug 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbi...Show more
SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service. Show less
2Gravitl
Netmaker
2Netmaker
Netmaker
Jun 17, 2026
Aug 24, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints. The issue is patched in 0.17.1 and...Show more
Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints. The issue is patched in 0.17.1 and fixed in 0.18.6. If users are using 0.17.1, they should run `docker pull gravitl/netmaker:v0.17.1` and `docker-compose up -d`. This will switch them to the patched users. If users are using v0.18.0-0.18.5, they should upgrade to v0.18.6 or later. As a workaround, someone who is using version 0.17.1 can pull the latest docker image of the backend and restart the server.Show less
1Sick
3Lms500 Firmware
Lms511 FirmwareLms531 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.