CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603. |
Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow a local attacker to obtain the hard-coded API key via reverse-engineeri...Show more |
1Getnexx 4Nxal 100 Firmware Nxg 100b FirmwareNxg 200 Firmware+1 moreJun 17, 2026 Apr 4, 2023 N/A· v4 10.0 CRITICAL· v3 N/A· v2 The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ...Show more |
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a determi...Show more |
1Propumpservice 1Osprey Pump Controller Firmware Jun 17, 2026 Mar 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Pass...Show more |
1Varta 8Element Backup Firmware Element S1 FirmwareElement S2 Firmware+5 moreJun 17, 2026 Mar 23, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network. |
MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There ha...Show more |
A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the aff...Show more |
PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user wit...Show more |
1Easyappointments 1Easy!appointments Jun 17, 2026 Mar 8, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
1Dos Osaka 2Rakuraku Pc Cloud Agent Ss1Jun 17, 2026 Mar 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result...Show more |
Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When using Gradio's share links (i.e. creatin...Show more |
ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attack...Show more |
Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services. |
Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, t...Show more |
3Bosswerk DeyeinverterRevolt Power3Inverter Firmware Inverter FirmwareInverter FirmwareJun 17, 2026 Feb 13, 2023 N/A· v4 6.8 MEDIUM· v3 3.7 LOW· v2 A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects some unknown processing of the component Access Point Setting Handler....Show more |
1Dell 1Powerpath Management Appliance Jun 17, 2026 Feb 11, 2023 N/A· v4 6.0 MEDIUM· v3 N/A· v2 PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information store...Show more |
1Dell 2Supportassist For Business Pcs Supportassist For Home PcsJun 17, 2026 Feb 11, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exp...Show more |
1Keystorage 1Global Facilities Management Software Jun 17, 2026 Feb 10, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependabi...Show more |
Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN. |