CWE-259— Use of Hard-coded Password
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.— MITRE CWE catalog
216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-259page 1 of 5
- CVE-2026-20316CRITICALCVSS 5.3EG 9.0⚠ KEV2026-07-29
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within t…
- CVE-2024-32741CRITICALCVSS 10.0EG 10.02024-05-14
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who …
- CVE-2022-45444CRITICALCVSS 10.0EG 10.02023-01-18
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select users in the application’s database. This could allow a remote attacker to login to the database w…
- CVE-2014-2363HIGHCVSS v2 10.0EG 10.02014-07-26
Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain access via a login request.
- CVE-2012-5862HIGHCVSS v2 10.0EG 10.02012-11-23
These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have una…
- CVE-2025-20286CRITICALCVSS 9.9EG 9.92025-06-04
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execut…
- CVE-2026-70403CRITICALCVSS 9.8EG 9.82026-09-04
XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.
- CVE-2026-35905CRITICALCVSS 9.8EG 9.82026-06-04
T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.
- CVE-2026-7251CRITICALCVSS 9.8EG 9.82026-05-26
Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using…
- CVE-2025-59388CRITICALCVSS 9.8EG 9.82026-03-12
A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following ver…
- CVE-2025-70041CRITICALCVSS 9.8EG 9.82026-03-11
An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master.
- CVE-2026-2616CRITICALCVSS 9.8EG 9.82026-02-17
A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials. The attack needs to be initiated withi…
- CVE-2026-25753CRITICALCVSS 9.8EG 9.82026-02-06
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, all…
- CVE-2025-15111CRITICALCVSS 9.8EG 9.82025-12-30
Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain fu…
- CVE-2025-11126CRITICALCVSS 9.8EG 9.82025-09-29
A security flaw has been discovered in Apeman ID71 218.53.203.117. This vulnerability affects unknown code of the file /system/www/system.ini. The manipulation results in hard-coded credentials. The attack may be performed from remote. The…
- CVE-2025-8974CRITICALCVSS 9.8EG 9.82025-08-14
A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/util/JwtHelper.java of the component JSON Web Toke…
- CVE-2025-8730CRITICALCVSS 9.8EG 9.82025-08-08
A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to hard-coded credentials. The …
- CVE-2025-30115CRITICALCVSS 9.8EG 9.82025-03-18
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Default Credentials Cannot Be Changed. It uses a fixed default SSID and password ("qwertyuiop"), which cannot be modified by users. The SSID is continuously broadca…
- CVE-2025-27638CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Hardcoded Password V-2024-013.
- CVE-2025-1100CRITICALCVSS 9.8EG 9.82025-02-12
A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to execute arbitrary code with root privileges via SSH.
- CVE-2024-4996CRITICALCVSS 9.8EG 9.82024-12-18
Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERP installations…
- CVE-2024-25825CRITICALCVSS 9.8EG 9.82024-10-09
FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.
- CVE-2024-43423CRITICALCVSS 9.8EG 9.82024-09-25
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.
- CVE-2023-37231CRITICALCVSS 9.8EG 9.82024-09-10
Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.
- CVE-2024-42639CRITICALCVSS 9.8EG 9.82024-08-16
H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root.
- CVE-2024-41616CRITICALCVSS 9.8EG 9.82024-08-06
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
- CVE-2024-7332CRITICALCVSS 9.8EG 9.82024-08-01
A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of…
- CVE-2024-36526CRITICALCVSS 9.8EG 9.82024-07-09
ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.
- CVE-2023-46685CRITICALCVSS 9.8EG 9.82024-07-08
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.
- CVE-2024-4708CRITICALCVSS 9.8EG 9.82024-07-02
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
- CVE-2024-38902CRITICALCVSS 9.8EG 9.82024-06-24
H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- CVE-2024-3700CRITICALCVSS 9.8EG 9.82024-06-10
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simpl…
- CVE-2024-3699CRITICALCVSS 9.8EG 9.82024-06-10
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet software versions…
- CVE-2024-1228CRITICALCVSS 9.8EG 9.82024-06-10
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia soft…
- CVE-2024-2420CRITICALCVSS 9.8EG 9.82024-05-30
LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypass authentication requirements.
- CVE-2024-34025CRITICALCVSS 9.8EG 9.82024-05-15
CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges.
- CVE-2024-33625CRITICALCVSS 9.8EG 9.82024-05-15
CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.
- CVE-2024-31810CRITICALCVSS 9.8EG 9.82024-05-14
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- CVE-2024-27488CRITICALCVSS 9.8EG 9.82024-04-08
Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the s…
- CVE-2024-28010CRITICALCVSS 9.8EG 9.82024-03-28
Use of Hard-coded Password in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2,…
- CVE-2023-50948CRITICALCVSS 9.8EG 9.82024-01-08
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal…
- CVE-2023-5222CRITICALCVSS 9.8EG 9.82023-09-27
A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of the component Web Management Interface. The manipulation lea…
- CVE-2023-41030CRITICALCVSS 9.8EG 9.82023-09-18
Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user.
- CVE-2023-2645CRITICALCVSS 9.8EG 9.82023-05-11
A vulnerability, which was classified as critical, was found in USR USR-G806 1.0.41. Affected is an unknown function of the component Web Management Page. The manipulation of the argument username/password with the input root leads to use …
- CVE-2022-41653CRITICALCVSS 9.8EG 9.82022-12-13
Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control the system.
- CVE-2022-22144CRITICALCVSS 9.8EG 9.82022-08-05
A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a known root passwor…
- CVE-2022-30271CRITICALCVSS 9.8EG 9.82022-07-26
The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to b…
- CVE-2017-20039CRITICALCVSS 9.8EG 9.82022-06-11
A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been classified as very critical. This affects an unknown part. The manipulation leads to weak authentication. It is possible to initiate the attack remotely.
- CVE-2021-34601CRITICALCVSS 9.8EG 9.82022-04-27
In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the password to gain administr…
- CVE-2021-38456CRITICALCVSS 9.8EG 9.82021-10-12
A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords
Map vulnerabilities like CWE-259 to your infrastructure
EchelonGraph correlates every CVE — across CWE-259 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →