CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample. |
A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a...Show more |
Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample. |
OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code, manipulate system data and disrupt service. |
1Vinchin 1Vinchin Backup And Recovery Jun 17, 2026 Aug 3, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw ex...Show more |
1Honeywell 1Safety Manager Firmware Jun 17, 2026 Jul 28, 2022 N/A· v4 4.6 MEDIUM· v3 N/A· v2 Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywell Experion PKS Safety Manager hardcoded credentials issue. The affected components are characterized...Show more |
1Ovarro 8Tbox Lt2 530 Firmware Tbox Lt2 532 FirmwareTbox Lt2 540 Firmware+5 moreJun 17, 2026 Jul 28, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key. |
In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10. |
The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being...Show more |
The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded...Show more |
1Emerson 24Deltav Distributed Control System Sq Controller Firmware Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 moreJun 17, 2026 Jul 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is di...Show more |
1Emerson 24Deltav Distributed Control System Sq Controller Firmware Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 moreJun 17, 2026 Jul 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-s...Show more |
1Emerson 24Deltav Distributed Control System Sq Controller Firmware Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 moreJun 17, 2026 Jul 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series,...Show more |
Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain sy...Show more |
1Bakerhughes 4Bently Nevada 3701/40 Firmware Bently Nevada 3701/44 FirmwareBently Nevada 3701/46 Firmware+1 moreJun 17, 2026 Jul 26, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interfac...Show more |
An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gai...Show more |
A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted reque...Show more |
1Ibm 1Security Verify Information Queue Jun 17, 2026 Jul 25, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or e...Show more |
1Atlassian 1Questions For Confluence Jun 17, 2026 Jul 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, un...Show more |
Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh. |