← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xxyopen
1Novel Plus
Jun 17, 2026
Sep 1, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.
1Honeywell
2Controledge Plc Firmware
Controledge Rtu Firmware
Jun 17, 2026
Aug 31, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH. The potentia...Show more
Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH. The potential impact is: Remote code execution, manipulate configuration, denial of service. The Honeywell ControlEdge PLC and RTU product line exposes an SSH service on port 22/TCP. Login as root to this service is permitted and credentials for the root user are hardcoded without automatically changing them upon first commissioning. The credentials for the SSH service are hardcoded in the firmware. The credentials grant an attacker access to a root shell on the PLC/RTU, allowing for remote code execution, configuration manipulation and denial of service.Show less
1Leyan
1Salary Management System
Jun 17, 2026
Aug 30, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote attacker can access, modify system data or disrupt service.
1Seiko Sol
1Skybridge Mb A200 Firmware
Jun 17, 2026
Aug 29, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh.
1Seiko Sol
2Skybridge Mb A100 Firmware
Skybridge Mb A110 Firmware
Jun 17, 2026
Aug 29, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.
1Totolink
1A810r Firmware
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
1Totolink
1A3000ru Firmware
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
1Totolink
1A860r Firmware
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
1Totolink
1N600r Firmware
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
1Totolink
1A950rg Firmware
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
1Totolink
1A800r Firmware
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
1Totolink
1A720r Firmware
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
1Nortekcontrol
1Emerge E3 Firmware
Jun 17, 2026
Aug 25, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have...Show more
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)Show less
1Malighting
1Grandma2 Light Firmware
Jun 17, 2026
Aug 21, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated networks. Also, the successor product, grandMA3, is not affected by this v...Show more
MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated networks. Also, the successor product, grandMA3, is not affected by this vulnerability.Show less
1Mapgis
1Mapgis Igserver
Jun 17, 2026
Aug 19, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion.
1Mapgis
1Igserver
Jun 17, 2026
Aug 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitrary file deletion.
1Dotnetcore
1Agileconfig
Jun 17, 2026
Aug 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.
1Device42
1Cmdb
Jun 17, 2026
Aug 17, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This iss...Show more
Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00.Show less
1Hjholdings
1Hulu
Jun 17, 2026
Aug 16, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by anal...Show more
'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.Show less
2Ivanti
Pulsesecure
2Connect Secure
Pulse Connect Secure
Jun 17, 2026
Aug 12, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-o...Show more
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.Show less