← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
87Ideapad 1 14ijl7 Firmware
Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 more
Jun 17, 2026
Aug 23, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credentia...Show more
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.Show less
1Arubanetworks
1Edgeconnect Sd Wan Orchestrator
Jun 17, 2026
Aug 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH...Show more
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host.Show less
1Nvki
1Intelligent Broadband Subscriber Gateway
Jul 9, 2026
Aug 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7...Show more
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the vulnerability discoverer.Show less
1Moxa
1Nport Iaw5000a I/o Firmware
Jun 17, 2026
Aug 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses a potential risk to the security and integrity of the affected device. This vulnerability is attrib...Show more
NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses a potential risk to the security and integrity of the affected device. This vulnerability is attributed to the presence of a hardcoded key, which could potentially facilitate firmware manipulation. Show less
2Cyberpower
Dataprobe
23Iboot Pdu4 C20 Firmware
Iboot Pdu4 N20 FirmwareIboot Pdu4a C10 Firmware+20 more
Jun 17, 2026
Aug 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating syst...Show more
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to read, modify, or delete arbitrary database records.Show less
1Dataprobe
22Iboot Pdu4 C20 Firmware
Iboot Pdu4 N20 FirmwareIboot Pdu4a C10 Firmware+19 more
Jun 17, 2026
Aug 14, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database.A malicious agent with the ability to execute operating syste...Show more
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database.A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to read, modify, or delete arbitrary database records.Show less
1Audiocodes
6405hd Firmware
445hd FirmwareC435hd Firmware+3 more
Jun 17, 2026
Aug 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encr...Show more
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.Show less
1Audiocodes
6405hd Firmware
445hd FirmwareC435hd Firmware+3 more
Jun 17, 2026
Aug 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information...Show more
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.Show less
1Intel
1Unison
Jun 17, 2026
Aug 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Use of hard-coded credentials in some Intel(R) Unison(TM) software before version 10.12 may allow an authenticated user user to potentially enable information disclosure via local access.
1Phoenixcontact
6Wp 6070 Wvps Firmware
Wp 6101 Wxps FirmwareWp 6121 Wxps Firmware+3 more
Jun 17, 2026
Aug 9, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session...Show more
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cookies created by the attacker are not sufficient to obtain a valid session on the device. Show less
1Qualcomm
120Aqt1000 Firmware
Ar8035 FirmwareCsra6620 Firmware+117 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
1Connectedio
1Connected Io
Jun 17, 2026
Aug 4, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect t...Show more
Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker and send messages on behalf of devices, impersonating them. in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.Show less
1Assaabloy
1Control Id Idsecure
Jun 17, 2026
Aug 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.
1Jbl
1Jbl Bar 5.1 Surround Firmware
Jun 17, 2026
Jul 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials
1Synel
1Synergy/a Firmware
Jun 17, 2026
Jul 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials
1Teleadapt
1Roomcast Ta 2400 Firmware
Jun 17, 2026
Jul 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.
1Fujitsu
11Ip 900d Firmware
Ip 900e FirmwareIp 900iid Firmware+8 more
Jun 17, 2026
Jul 26, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission....Show more
Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E firmware versions V01L001 to V01L053, IP-HE950D firmware versions V01L001 to V01L053, IP-HE900E firmware versions V01L001 to V01L010, IP-HE900D firmware versions V01L001 to V01L004, IP-900E / IP-920E firmware versions V01L001 to V02L061, IP-900D / IP-900ⅡD / IP-920D firmware versions V01L001 to V02L061, IP-90 firmware versions V01L001 to V01L013, and IP-9610 firmware versions V01L001 to V02L007.Show less
1Iagona
1Scrutisweb
Jun 17, 2026
Jul 18, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a cryptographic vulnerability that could allow an unauthenticated user to decrypt encrypted passwords into plaintext.
1Sonicwall
2Analytics
Global Management System
Jun 17, 2026
Jul 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
1Smartsoft
1Smartbpm.net
Jun 17, 2026
Jul 10, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execut...Show more
SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execute submission and approval processes.Show less