← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sonicwall
5Sma 6200 Firmware
Sma 6210 FirmwareSma 7200 Firmware+2 more
Jun 17, 2026
May 13, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.
1Inhandnetworks
1Ir302 Firmware
Jun 17, 2026
May 12, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can se...Show more
A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1Inhandnetworks
1Ir302 Firmware
Jun 17, 2026
May 12, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability exists in the router configuration export functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to increased privileges. An attacker can...Show more
An information disclosure vulnerability exists in the router configuration export functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.Show less
1Ibm
1Spectrum Virtualize
Jun 17, 2026
May 11, 2022
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM X-Force ID: 212609.
1Pingidentity
1Pingid Integration For Windows Login
Jun 17, 2026
May 4, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnera...Show more
Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials.Show less
1Automationanywhere
1Automation 360
Jun 17, 2026
Apr 29, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.
1Bender
2Cc612 Firmware
Icc15xx Firmware
Jun 17, 2026
Apr 27, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the passwor...Show more
In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the password to gain administrative access to the web-UI.Show less
1Apache
1Doris
Jun 17, 2026
Apr 26, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
1Terra Master
1Tos
Jun 17, 2026
Apr 25, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused usi...Show more
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused using a null/empty hash and allow an unauthenticated attacker to login as guest.Show less
1Asus
1Webstorage
Jun 17, 2026
Apr 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A su...Show more
ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the attacker to access, modify or delete this user account information.Show less
1Cisco
2Umbrella
Umbrella Virtual Appliance
Jun 22, 2026
Apr 21, 2022
N/A· v4
7.5 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a s...Show more
A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a man-in-the-middle attack on an SSH connection to the Umbrella VA. A successful exploit could allow the attacker to learn the administrator credentials, change configurations, or reload the VA. Note: SSH is not enabled by default on the Umbrella VA.Show less
1Databasir Project
1Databasir
Jun 17, 2026
Apr 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability. An attacker can use hard coding to generate login credentials of...Show more
Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability. An attacker can use hard coding to generate login credentials of any user and log in to the service background located at different IP addresses.Show less
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Apr 18, 2022
N/A· v4
6.8 MEDIUM· v3
7.1 HIGH· v2
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default ad...Show more
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.Show less
1Bbraun
2Datamodule Compactplus
Spacecom
Jun 17, 2026
Apr 14, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Hard-coded credentials in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enable attackers with command line access to access the device’s Wi-Fi module...Show more
Hard-coded credentials in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enable attackers with command line access to access the device’s Wi-Fi module.Show less
1Swiftsensors
1Sg3 1010 Firmware
Jun 17, 2026
Apr 14, 2022
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send...Show more
An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1Moxa
1Mxview
Jun 17, 2026
Apr 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to tr...Show more
An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to trigger this vulnerability.Show less
1Citrix
14Sd Wan 1000 Firmware
Sd Wan 1100 FirmwareSd Wan 110 Firmware+11 more
Jun 17, 2026
Apr 13, 2022
N/A· v4
2.7 LOW· v3
6.8 MEDIUM· v2
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
1Dell
1Emc Powerscale Onefs
Jun 17, 2026
Apr 12, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. The at...Show more
Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. The attacker can exploit this vulnerability to take the switch offline.Show less
1Secom
2Dr.id Access Control
Dr.id Attendance System
Jun 17, 2026
Apr 7, 2022
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify...Show more
Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service.Show less
1Fortinet
1Fortiedr
Jun 17, 2026
Apr 6, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow a local attacker to disable and uninstall the collectors fr...Show more
A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow a local attacker to disable and uninstall the collectors from the end-points within the same deployment.Show less