← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
3Spectrum Power 4
Spectrum Power 7Spectrum Power Microgrid Management System
Jun 17, 2026
Jun 14, 2022
N/A· v4
8.8 HIGH· v3
5.4 MEDIUM· v2
A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker...Show more
A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker could log into the component Shared HIS used in Spectrum Power systems by using an account with default credentials. A successful exploitation could allow the attacker to access the component Shared HIS with administrative privileges.Show less
1Rakuten
1Casa
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the root privilege and perform an arbitrary operation.
1Sicunet
1Access Control
Nov 21, 2024
Jun 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been classified as very critical. This affects an unknown part. The manipulation leads to weak authentication. It is possible to initiate the attack...Show more
A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been classified as very critical. This affects an unknown part. The manipulation leads to weak authentication. It is possible to initiate the attack remotely.Show less
1Igel
1Universal Management Suite
Jun 17, 2026
Jun 9, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncrypter class allows an attacker, who has discovered encrypted LDAP bind credentials, to decrypt those...Show more
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncrypter class allows an attacker, who has discovered encrypted LDAP bind credentials, to decrypt those credentials using a static 8-byte DES key.Show less
1Igel
1Universal Management Suite
Jun 17, 2026
Jun 9, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredentials class allows an attacker, who has discovered encrypted superuser credentials, to decrypt those c...Show more
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredentials class allows an attacker, who has discovered encrypted superuser credentials, to decrypt those credentials using a static 8-byte DES key.Show less
1Dlink
1Dir 890l Firmware
Jun 17, 2026
Jun 3, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php
1Totolink
1Ex1200t Firmware
Jun 17, 2026
Jun 3, 2022
N/A· v4
4.3 MEDIUM· v3
5.0 MEDIUM· v2
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and password exists in the firmware.
1Schneider Electric
2Wiser Smart Eer21000 Firmware
Wiser Smart Eer21001 Firmware
Jun 17, 2026
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtained. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
1Owllabs
1Meeting Owl Pro Firmware
Jun 17, 2026
Jun 2, 2022
N/A· v4
8.8 HIGH· v3
5.4 MEDIUM· v2
Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth broadcast data.
1Owllabs
1Meeting Owl Pro Firmware
Jun 17, 2026
Jun 2, 2022
N/A· v4
7.4 HIGH· v3
3.3 LOW· v2
Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a certain c 150 value.
1Usr
5Usr G800v2 Firmware
Usr G806 FirmwareUsr G807 Firmware+2 more
Jun 17, 2026
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device.
1Linkplay
1Sound Bar
Jun 17, 2026
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in linkplay antifactory
1Kuka
2Kr C4 Firmware
Kss
Jun 17, 2026
May 26, 2022
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.
1Kuka
2Kr C4 Firmware
Kss
Jun 17, 2026
May 26, 2022
N/A· v4
8.8 HIGH· v3
5.0 MEDIUM· v2
An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.
1Telecomsoftware
2Samwin Agent
Samwin Contact Center
Nov 21, 2024
May 24, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A vulnerability was found in Telecommunication Software SAMwin Contact Center Suite 5.1. It has been rated as critical. Affected by this issue is the function getCurrentDBVersion in the library SAMwinLIBVB.dll of the cre...Show more
A vulnerability was found in Telecommunication Software SAMwin Contact Center Suite 5.1. It has been rated as critical. Affected by this issue is the function getCurrentDBVersion in the library SAMwinLIBVB.dll of the credential handler. Authentication is possible with hard-coded credentials. Upgrading to version 6.2 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Pagerduty
1Rundeck
Jun 17, 2026
May 20, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated SSH keypair. If the id_rsa.pub public key...Show more
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated SSH keypair. If the id_rsa.pub public key of the keypair was copied to authorized_keys files on remote host, those hosts would allow access to anyone with the exposed private credentials. This misconfiguration only impacts Rundeck Docker instances of PagerDuty® Process Automation On Prem (formerly Rundeck) version 4.0 and earlier, not Debian, RPM or .WAR. Additionally, the id_rsa.pub file would have to be copied from the Docker image filesystem contents without overwriting it and used to configure SSH access on a host. A patch on Rundeck's `main` branch has removed the pre-generated SSH key pair, but it does not remove exposed keys that have been configured. To patch, users must run a script on hosts in their environment to search for exposed keys and rotate them. Two workarounds are available: Do not use any pre-existing public key file from the rundeck docker images to allow SSH access by adding it to authorized_keys files and, if you have copied the public key file included in the docker image, remove it from any authorized_keys files.Show less
1Lenovo
5A1 Firmware
T1 FirmwareT2 Firmware+2 more
Jun 17, 2026
May 18, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local net...Show more
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.Show less
1Lenovo
5A1 Firmware
T1 FirmwareT2 Firmware+2 more
Jun 17, 2026
May 18, 2022
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.
1Totolink
1A3100r Firmware
Jun 17, 2026
May 18, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for root stored in the component /etc/shadow.sample.
1Totolink
1A3100r Firmware
Jun 17, 2026
May 18, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for the telnet service stored in the component /web_cste/cgi-bin/product.ini.