← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bosch
4Access Management System
Access Professional EditionAmc2 Firmware+1 more
Jun 17, 2026
Jan 19, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the...Show more
Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this vulnerability to decrypt and modify network traffic, decrypt and further investigate the device\'s firmware file, and change the device configuration. The attacker needs to have access to the local network, typically even the same subnet.Show less
1Jmty
1Jimoty
Jun 17, 2026
Jan 17, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Jimoty App for Android versions prior to 3.7.42 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.
1Le Yan Dental Management System Project
1Le Yan Dental Management System
Jun 17, 2026
Jan 14, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Le-yan dental management system contains a hard-coded credentials vulnerability in the web page source code, which allows an unauthenticated remote attacker to acquire administrator’s privilege and control the system...Show more
The Le-yan dental management system contains a hard-coded credentials vulnerability in the web page source code, which allows an unauthenticated remote attacker to acquire administrator’s privilege and control the system or disrupt service.Show less
1Tibco
1Ftl
Jun 17, 2026
Jan 11, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication...Show more
The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret used in the default realm server of the affected system. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.7.2 and below, TIBCO FTL - Developer Edition: versions 6.7.2 and below, and TIBCO FTL - Enterprise Edition: versions 6.7.2 and below.Show less
1Puddingbot Project
1Puddingbot
Jun 17, 2026
Jan 11, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicly exposed in main.py, making it accessible to malicious actors. The bot token has been revoked and new version is already...Show more
PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicly exposed in main.py, making it accessible to malicious actors. The bot token has been revoked and new version is already running on the server. As of time of publication, the maintainers are planning to update code to reflect this change at a later date.Show less
1Siemens
4Cp 8000 Master Module With I/o 25/+70 Firmware
Cp 8000 Master Module With I/o 40/+70 FirmwareCp 8021 Master Module Firmware+1 more
Jun 17, 2026
Jan 11, 2022
N/A· v4
8.8 HIGH· v3
8.5 HIGH· v2
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP...Show more
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). An undocumented debug port uses hard-coded default credentials. If this port is enabled by a privileged user, an attacker aware of the credentials could access an administrative debug shell on the affected device.Show less
1Qxip
1Homer Webapp
Jun 17, 2026
Jan 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.
1Apache
1Kylin
Jun 17, 2026
Jan 6, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and...Show more
Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and IV. If users use class PasswordPlaceholderConfigurer to encrypt their password and configure it into kylin's configuration file, there is a risk that the password may be decrypted. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.Show less
1Controlup
1Controlup Agent
Jun 17, 2026
Jan 4, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A hardcoded key in ControlUp Real-Time Agent (cuAgent.exe) before 8.2.5 may allow a potential attacker to run OS commands via a WCF channel.
1Netgear
1R6700 Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted/obfu...Show more
Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted/obfuscated. By extracting the configuration using readily available public tools, a user can reconfigure settings not intended to be manipulated, repackage the configuration, and restore a backup causing these settings to be changed.Show less
1Netgear
1Rax43 Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted. This encryption...Show more
Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted. This encryption is accomplished via a password-protected zip file with a hardcoded password (RAX50w!a4udk). By unzipping the configuration using this password, a user can reconfigure settings not intended to be manipulated, re-zip the configuration, and restore a backup causing these settings to be changed.Show less
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted using a hardcoded pa...Show more
Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted using a hardcoded password of "12345678".Show less
1Dlink
1Dir 2640 Us Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gain administrative access to the zebra or ripd those services. Both are r...Show more
Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gain administrative access to the zebra or ripd those services. Both are running with root privileges on the router (i.e., as the "admin" user, UID 0).Show less
1Solarwinds
1Webhelpdesk
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the datab...Show more
Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password hashes of the users or insert arbitrary data into the database.Show less
1Philips
2Intellibridge Ec40 Firmware
Intellibridge Ec80 Firmware
Jun 17, 2026
Dec 27, 2021
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external componen...Show more
IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.Show less
1Netgear
1Xr1000 Firmware
Jun 17, 2026
Dec 26, 2021
N/A· v4
8.8 HIGH· v3
7.5 HIGH· v2
NETGEAR XR1000 devices before 1.0.0.58 are affected by a hardcoded password.
1Netgear
3Rbk352 Firmware
Rbr350 FirmwareRbs350 Firmware
Jun 17, 2026
Dec 26, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.
1Netgear
3Rbk352 Firmware
Rbr350 FirmwareRbs350 Firmware
Jun 17, 2026
Dec 26, 2021
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.
1Acclaimsystems
1Usaherds
Jun 17, 2026
Dec 21, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
1Fortinet
2Forticlient
Forticlient Endpoint Management Server
Jun 17, 2026
Dec 16, 2021
N/A· v4
7.5 HIGH· v3
5.4 MEDIUM· v2
A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, Fort...Show more
A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and below may allow an unauthenticated and network adjacent attacker to perform a man-in-the-middle attack between the EMS and the FCT via the telemetry protocol.Show less