CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker on the network to disguise as and forge messages from other collectors. |
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to...Show more |
Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as root users via extracting a key from the software. |
2Belden Schneider Electric13Eagle 20 Tofino 943 987 501 Tx/tx Firmware Eagle 20 Tofino 943 987 502 Tx/mm FirmwareEagle 20 Tofino 943 987 504 Mm/tx Firmware+10 moreJun 17, 2026 Apr 3, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in...Show more |
In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telne...Show more |
1Baicells 2Neutrino 430 Firmware Nova436q FirmwareJun 17, 2026 Mar 30, 2022 N/A· v4 9.8 CRITICAL· v3 7.8 HIGH· v2 Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored...Show more |
1Nuuo 1Network Video Recorder Firmware Jul 9, 2026 Mar 29, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 NUUO v03.11.00 was discovered to contain access control issue. |
ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user's data. Attackers who are able to gain remote or local access to the system are able to read and mo...Show more |
GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR. |
1Garo 3Wallbox Glb Firmware Wallbox Gtb FirmwareWallbox Gtc FirmwareJun 17, 2026 Mar 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat...Show more |
1Ge 3Rt430 Firmware Rt431 FirmwareRt434 FirmwareJun 17, 2026 Mar 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, attackers would be able to intercept and decrypt encrypted traffic through...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreJun 17, 2026 Mar 18, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of enc...Show more |
RunAsSpc 4.0 uses a universal and recoverable encryption key. In possession of a file encrypted by RunAsSpc, an attacker can recover the credentials that were used. |
1Ptc 2Axeda Agent Axeda Desktop ServerJun 17, 2026 Mar 16, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated a...Show more |
3Bluproducts LunaWikomobile5G90 Firmware G9 FirmwareSimo Firmware+2 moreJun 17, 2026 Mar 11, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-party apps can provide a spoofed software update file that contains an arbitrary shell script and ar...Show more |
1Yokogawa 3Centum Vp Entry Firmware Centum Vp FirmwareExaopcJun 17, 2026 Mar 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00 |
1Yokogawa 3Centum Vp Entry Firmware Centum Vp FirmwareExaopcJun 17, 2026 Mar 11, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Ex...Show more |
1Freetakserver Ui Project 1Freetakserver Ui Jun 17, 2026 Mar 11, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. |
1Phicomm 2K2 Firmware K3c FirmwareJun 17, 2026 Mar 10, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the device over telnet. The builds of telnetd_startup included in the versi...Show more |
1Phicomm 5K2 Firmware K2g FirmwareK2p Firmware+2 moreJun 17, 2026 Mar 10, 2022 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via an unprotected UART port on the device. The same port exposes an unaut...Show more |