← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1A3002ru Firmware
Jun 17, 2026
Aug 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.
1Tcl
1Linkhub Mesh Wifi Ac1200
Jun 17, 2026
Aug 5, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a...Show more
A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a known root password. An attacker does not have to do anything to trigger this vulnerability.Show less
1Totolink
1A3600r Firmware
Jun 17, 2026
Aug 4, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.
1Omicard Edm Project
1Omicard Edm
Jun 17, 2026
Aug 4, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code, manipulate system data and disrupt service.
1Vinchin
1Vinchin Backup And Recovery
Jun 17, 2026
Aug 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw ex...Show more
This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MySQL server. The server uses a hard-coded password for the administrator user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17139.Show less
1Honeywell
1Safety Manager Firmware
Jun 17, 2026
Jul 28, 2022
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywell Experion PKS Safety Manager hardcoded credentials issue. The affected components are characterized...Show more
Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywell Experion PKS Safety Manager hardcoded credentials issue. The affected components are characterized as: POLO bootloader. The potential impact is: Manipulate firmware. The Honeywell Experion PKS Safety Manager utilizes the DCOM-232/485 serial interface for firmware management purposes. When booting, the Safety Manager exposes the Enea POLO bootloader via this interface. Access to the boot configuration is controlled by means of credentials hardcoded in the Safety Manager firmware. The credentials for the bootloader are hardcoded in the firmware. An attacker with access to the serial interface (either through physical access, a compromised EWS or an exposed serial-to-ethernet gateway) can utilize these credentials to control the boot process and manipulate the unauthenticated firmware image (see FSCT-2022-0054).Show less
1Ovarro
8Tbox Lt2 530 Firmware
Tbox Lt2 532 FirmwareTbox Lt2 540 Firmware+5 more
Jun 17, 2026
Jul 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.
1Veritas
1Netbackup
Jun 17, 2026
Jul 27, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
1Motorola
1Ace1000 Firmware
Jun 17, 2026
Jul 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being...Show more
The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB mode using a hardcoded key. Similarly, the ACE1000 RTU can route MDLC traffic over Extended Command and Management Protocol (XCMP) and Network Layer (XNL) networks via the MDLC driver. Authentication to the XNL port is protected by TEA in ECB mode using a hardcoded key.Show less
1Motorola
1Ace1000 Firmware
Jun 17, 2026
Jul 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded...Show more
The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.Show less
1Emerson
24Deltav Distributed Control System Sq Controller Firmware
Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 more
Jun 17, 2026
Jul 26, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is di...Show more
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350.Show less
1Emerson
24Deltav Distributed Control System Sq Controller Firmware
Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 more
Jun 17, 2026
Jul 26, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-s...Show more
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.Show less
1Emerson
24Deltav Distributed Control System Sq Controller Firmware
Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 more
Jun 17, 2026
Jul 26, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series,...Show more
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.Show less
1Emerson
1Openbsi
Jun 17, 2026
Jul 26, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain sy...Show more
Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive utilities.Show less
1Bakerhughes
4Bently Nevada 3701/40 Firmware
Bently Nevada 3701/44 FirmwareBently Nevada 3701/46 Firmware+1 more
Jun 17, 2026
Jul 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interfac...Show more
The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.Show less
1Filewave
1Filewave
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gai...Show more
An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.Show less
1Filewave
1Filewave
Jun 17, 2026
Jul 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted reque...Show more
A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.Show less
1Ibm
1Security Verify Information Queue
Jun 17, 2026
Jul 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or e...Show more
IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 230817.Show less
1Atlassian
1Questions For Confluence
Jun 17, 2026
Jul 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, un...Show more
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.Show less
1Wavlink
1Wl Wn530hg4 Firmware
Jun 17, 2026
Jul 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh.