← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Smartsoft
1Smartbpm.net
Jun 17, 2026
Jul 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt servic...Show more
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.Show less
1Piigab
1M Bus 900s Firmware
Jun 17, 2026
Jul 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
1Loxone
1Miniserver Go Gen 2 Firmware
Jun 17, 2026
Jul 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC address. This allows a local user to calculate the root password and escalate privileges.
1Ami
1Megarac Sp X
Jun 17, 2026
Jul 5, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
AMI SPx contains a vulnerability in the BMC where a valid user may cause a use of hard-coded credentials. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.
1Ami
1Megarac Sp X
Jun 17, 2026
Jul 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerability may lead to a loss of confidentiality,...Show more
AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability. Show less
1Kingstemple
1The King's Temple Church Website
Jun 17, 2026
Jul 3, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintenti...Show more
`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintentionally committed and subsequently exposed in the codebase. If an unauthorized party gains access to this key, they could potentially carry out transactions on behalf of the organization, leading to financial losses. Additionally, they could access sensitive customer information, leading to privacy violations and potential legal implications. The affected component is the codebase of our project, specifically the file(s) where the Stripe API key is embedded. The key should have been stored securely, and not committed to the codebase. The maintainers plan to revoke the leaked Stripe API key immediately, generate a new one, and not commit the key to the codebase.Show less
1Uzabase
1Newspicks
Jun 17, 2026
Jun 30, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
"NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard-coded credentials, which may allow a local attacker to analyze data in the app and to obtain API ke...Show more
"NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard-coded credentials, which may allow a local attacker to analyze data in the app and to obtain API key for an external service.Show less
1Advantech
1R Seenet
Jun 17, 2026
Jun 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users.
1Enphase
1Installer Toolkit
Jun 17, 2026
Jun 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.
1Hpe
1Insight Remote Support
Jun 17, 2026
Jun 16, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information.
1Nokia
1Asika Airscale Firmware
Jun 17, 2026
Jun 16, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time installed) default SSH public/private key values that are specific to a...Show more
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time installed) default SSH public/private key values that are specific to a network operator. As a result, the CSP internal BTS network SSH server (disabled by default) continues to apply the default SSH public/private key values. These keys don't give access to BTS, because service user authentication is username/password-based on top of SSH. Nokia factory installed default SSH keys are meant to be changed from operator-specific values during the BTS deployment commissioning phase. However, before the 21B release, BTS commissioning manuals did not provide instructions to change default SSH keys (to BTS operator-specific values). This leads to a possibility for malicious operations staff (inside a CSP network) to attempt MITM exploitation of BTS service user access, during the moments that SSH is enabled for Nokia service personnel to perform troubleshooting activities.Show less
1Otcms
1Otcms
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
5.8 MEDIUM· v2
A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input admin leads to use of hard-coded password....Show more
A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input admin leads to use of hard-coded password. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231508.Show less
1Rockwellautomation
2Factorytalk Policy Manager
Factorytalk System Services
Jun 17, 2026
Jun 13, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies.  Hard-coded cryptographic key may lead to privilege escalation.  This vulnerability may allow a lo...Show more
Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies.  Hard-coded cryptographic key may lead to privilege escalation.  This vulnerability may allow a local, authenticated non-admin user to generate an invalid administrator cookie giving them administrative privileges to the FactoryTalk Policy Manger database. This may allow the threat actor to make malicious changes to the database that will be deployed when a legitimate FactoryTalk Policy Manager user deploys a security policy model. User interaction is required for this vulnerability to be successfully exploited. Show less
1Siemens
1Cpci85 Firmware
Jun 17, 2026
Jun 13, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain the hash of the root password in a hard-coded form...Show more
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain the hash of the root password in a hard-coded form, which could be exploited for UART console login to the device. An attacker with direct physical access could exploit this vulnerability.Show less
1Hitrontech
1Coda 5310 Firmware
Jun 17, 2026
Jun 2, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Hitron CODA-5310 has hard-coded encryption/decryption keys in the program code. A remote attacker authenticated as an administrator can decrypt system files using the hard-coded keys for file access, modification, and ca...Show more
Hitron CODA-5310 has hard-coded encryption/decryption keys in the program code. A remote attacker authenticated as an administrator can decrypt system files using the hard-coded keys for file access, modification, and cause service disruption.Show less
1Mitsubishielectric
4Fx5 Enet/ip Firmware
Rj71eip91 FirmwareSw1dnn Eipct Bd Firmware+1 more
Jun 17, 2026
Jun 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenti...Show more
Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to obtain a hard-coded password and access to the module via FTP.Show less
1Sprecher Automation
9Sprecon E C Firmware
Sprecon E P Dl6 1 FirmwareSprecon E P Dq6 1 Firmware+6 more
Jun 17, 2026
Jun 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines.
1Draytek
72Myvigor
Vigor1000b FirmwareVigor130 Firmware+69 more
Jun 17, 2026
Jun 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded...Show more
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.Show less
1Saison
1Dataspider Servista
Jun 17, 2026
Jun 1, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration software. ScriptRunner and ScriptRunner for Amazon SQS are used to start the configured processes o...Show more
DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration software. ScriptRunner and ScriptRunner for Amazon SQS are used to start the configured processes on DataSpider Servista. The cryptographic key is embedded in ScriptRunner and ScriptRunner for Amazon SQS, which is common to all users. If an attacker who can gain access to a target DataSpider Servista instance and obtain a Launch Settings file of ScriptRunner and/or ScriptRunner for Amazon SQS, the attacker may perform operations with the user privilege encrypted in the file. Note that DataSpider Servista and some of the OEM products are affected by this vulnerability. For the details of affected products and versions, refer to the information listed in [References].Show less
1Rozcom
1Rozcom Client
Jun 17, 2026
May 30, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
ROZCOM client CWE-798: Use of Hard-coded Credentials