← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
1Tapo C310 Firmware
Jun 17, 2026
Apr 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603.
1Wolt
1Wolt Delivery
Jun 17, 2026
Apr 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow a local attacker to obtain the hard-coded API key via reverse-engineeri...Show more
Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow a local attacker to obtain the hard-coded API key via reverse-engineering the application binary.Show less
1Getnexx
4Nxal 100 Firmware
Nxg 100b FirmwareNxg 200 Firmware+1 more
Jun 17, 2026
Apr 4, 2023
N/A· v4
10.0 CRITICAL· v3
N/A· v2
The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ...Show more
The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.Show less
1Rocketsoftware
2Unidata
Universe
Jun 17, 2026
Mar 29, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a determi...Show more
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.Show less
1Propumpservice
1Osprey Pump Controller Firmware
Jun 17, 2026
Mar 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Pass...Show more
Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot be changed through any normal operation of the device.Show less
1Varta
8Element Backup Firmware
Element S1 FirmwareElement S2 Firmware+5 more
Jun 17, 2026
Mar 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
1Mgt Commerce
1Cloudpanel
Jun 17, 2026
Mar 21, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There ha...Show more
MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There has been no indication from the vendor this has been addressed in version 2.2.1.Show less
1Propius
1Machineselector
Jun 17, 2026
Mar 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the aff...Show more
A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system.Show less
1Panindex Project
1Panindex
Jun 17, 2026
Mar 13, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user wit...Show more
PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user with admin privileges. Version 3.1.3 has a patch for the issue. As a workaround, one may change the JWT key in the source code before compiling the project. Show less
1Easyappointments
1Easy!appointments
Jun 17, 2026
Mar 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
1Dos Osaka
2Rakuraku Pc Cloud Agent
Ss1
Jun 17, 2026
Mar 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result...Show more
Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22336 vulnerabilities together, it may allow a remote attacker to execute an arbitrary code with SYSTEM privileges by sending a specially crafted script to the affected device.Show less
1Gradio Project
1Gradio
Jun 17, 2026
Feb 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When using Gradio's share links (i.e. creatin...Show more
Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When using Gradio's share links (i.e. creating a Gradio app and then setting `share=True`), a private SSH key is sent to any user that connects to the Gradio machine, which means that a user could access other users' shared Gradio demos. From there, other exploits are possible depending on the level of access/exposure the Gradio app provides. This issue is patched in version 3.13.1, however, users are recommended to update to 3.19.1 or later where the FRP solution has been properly tested. Show less
1Thingsboard
1Thingsboard
Jun 17, 2026
Feb 23, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attack...Show more
ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the application server or its source code.)Show less
1Prolink2u
1Prs1841 Firmware
Jun 17, 2026
Feb 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.
1Echelon
1I.lon Vision
Jun 17, 2026
Feb 13, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, t...Show more
Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user interface and file transfer protocol (FTP) server. Show less
3Bosswerk
DeyeinverterRevolt Power
3Inverter Firmware
Inverter FirmwareInverter Firmware
Jun 17, 2026
Feb 13, 2023
N/A· v4
6.8 MEDIUM· v3
3.7 LOW· v2
A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects some unknown processing of the component Access Point Setting Handler....Show more
A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects some unknown processing of the component Access Point Setting Handler. The manipulation with the input 12345678 leads to use of hard-coded password. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version MW3_16U_5406_1.53 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-220769 was assigned to this vulnerability.Show less
1Dell
1Powerpath Management Appliance
Jun 17, 2026
Feb 11, 2023
N/A· v4
6.0 MEDIUM· v3
N/A· v2
PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information store...Show more
PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the application. Show less
1Dell
2Supportassist For Business Pcs
Supportassist For Home Pcs
Jun 17, 2026
Feb 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exp...Show more
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. Show less
1Keystorage
1Global Facilities Management Software
Jun 17, 2026
Feb 10, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependabi...Show more
Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependability of electronic key boxes.Show less
1Samsung
1Android
Jun 17, 2026
Feb 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.