← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kubernetes
1Minikube
Jun 17, 2026
May 24, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
This vulnerability enables ssh access to minikube container using a default password.
1Jins
1Jins Meme Firmware
Jun 17, 2026
May 23, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
JINS MEME CORE Firmware version 2.2.0 and earlier uses a hard-coded cryptographic key, which may lead to data acquired by a sensor of the affected product being decrypted by a network-adjacent attacker.
1Contec
2Sv Cpt Mc310 Firmware
Sv Cpt Mc310f Firmware
Jun 17, 2026
May 23, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Use of hard-coded credentials exists in SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10, and SV-CPT-MC310F versions prior to Ver.8.10, which may allow a remote authenticated attacker to login the affected produ...Show more
Use of hard-coded credentials exists in SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10, and SV-CPT-MC310F versions prior to Ver.8.10, which may allow a remote authenticated attacker to login the affected product with an administrative privilege and perform an unintended operation.Show less
1Birddog
44k Quad Firmware
A300 FirmwareMini Firmware+1 more
Jun 17, 2026
May 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.
1Moxa
1Mxsecurity
Jun 17, 2026
May 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based AP...Show more
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs. Show less
1Tenda
1Cp3 Firmware
Jun 17, 2026
May 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.
1Tenda
1Cp3 Firmware
Jun 17, 2026
May 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.
1Tenda
1Cp3 Firmware
Jun 17, 2026
May 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TE...Show more
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.Show less
1Fortinet
2Fortinac
Fortinac F
Jun 17, 2026
May 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an authenticated att...Show more
A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an authenticated attacker to access to the database via shell commands.Show less
1Echa.europa
1Iuclid
Jun 17, 2026
May 2, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.
1Sage
1Sage 300
Jun 17, 2026
Apr 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers t...Show more
Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL connection strings.Show less
1Sage
1Sage 300
Jun 17, 2026
Apr 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for the PORTAL database found in the "dbconfig....Show more
The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for the PORTAL database found in the "dbconfig.xml". This issue could allow attackers to obtain access to the SQL database.Show less
1Sage
1Sage 300
Jun 17, 2026
Apr 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attackers to login to the Solr dashboard with ad...Show more
The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attackers to login to the Solr dashboard with admin privileges and access sensitive information.Show less
1Sage
1Sage 300
Jun 17, 2026
Apr 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database...Show more
The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables.Show less
1Synopsys
1Code Dx
Jun 17, 2026
Apr 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to th...Show more
Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating the token. A malicious actor who creates this token can supply it to a separate Code Dx system, provided they know the username they want to impersonate, and impersonate the user.  Score 6.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C Show less
1Zohocorp
3Manageengine Access Manager Plus
Manageengine Pam360Manageengine Password Manager Pro
Jun 17, 2026
Apr 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to mo...Show more
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user.Show less
1Fighting Cock Information System Project
1Fighting Cock Information System
Jun 17, 2026
Apr 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials.
1Pwsdashboard
1Personal Weather Station Dashboard
Jun 17, 2026
Apr 25, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.php. Attacks can use the PWS_printfile.php, PWS_frame_text.php, PWS_lis...Show more
PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.php. Attacks can use the PWS_printfile.php, PWS_frame_text.php, PWS_listfile.php, PWS_winter.php, and PWS_easyweathersetup.php endpoints. A contributing factor is a hardcoded login password of support, which is not documented. (This is not the same as the documented setup password, which is 12345.) The issue was fixed in late 2022.Show less
1Nuxtlabs
1Nuxt
Jun 17, 2026
Apr 18, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.
1Electra Air
1Central Ac Unit Firmware
Jun 17, 2026
Apr 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.