CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they wer...Show more |
1Goldshell 1Goldshell Miner Firmware Jun 17, 2026 Jul 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect via the SSH protocol (port 22). |
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one de...Show more |
This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104, update_i50_v1.0.55_b20200509, update_x6_v2.1.2_b202001127, update_b5_v2.0.9_b20200706. This vulner...Show more |
1Nexans 13Gigaswitch 641 Desk V5 Sfp Vi Firmware Gigaswitch 642 Desk V5 Sfp 2vi FirmwareGigaswitch V5 2tp(pd F+) Sfp Vi 54vdc Firmware+10 moreJun 17, 2026 Jul 17, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201. |
1Infiray 1Iray A8z3 Firmware Jun 17, 2026 Jul 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains hardcoded credentials to the web application. Because these accounts cannot be deactivated or have t...Show more |
Disclosure of information - the system allows you to view usernames and passwords without permissions, thus it will be possible to enter the system. Path access: http://api/sys_username_passwd.cmd - The server loads the...Show more |
Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This allows attackers to access sensitive information such as user credentials and certificates. |
1Verizon 2Lvskihp Indoorunit Firmware Lvskihp Outdoorunit FirmwareJun 17, 2026 Jul 14, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static certificate for access control. This certificate is embedded in the firmwar...Show more |
kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroC...Show more |
IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or en...Show more |
1Ibm 1Security Siteprotector System Jun 17, 2026 Jul 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption o...Show more |
1Omron 57Na5 12w Firmware Na5 15w FirmwareNa5 7w Firmware+54 moreJun 17, 2026 Jul 4, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation contr...Show more |
The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password. |
1Yokogawa 2Stardom Fcj Firmware Stardom Fcn FirmwareJun 17, 2026 Jun 28, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which may allow an attacker with an administrative privilege to read/change configuration settings or update...Show more |
1Southrivertech 1Titan Ftp Server Nextgen Jun 17, 2026 Jun 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default d...Show more |
1Proietti 1Planet Time Enterprise Jun 17, 2026 Jun 17, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter. |
1Antminer Monitor Project 1Antminer Monitor Jun 17, 2026 Jun 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however i...Show more |
A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the Service Browser which itroduces hard-coded credentials. Attacking locally is a requirement. It is recommended to change th...Show more |
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9), Teamcenter V13.1 (All versions < V13.1.0.9), Teamcenter V13.2 (All versions < V13.2.0.9),...Show more |