CWE-259— Use of Hard-coded Password
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.— MITRE CWE catalog
216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-259page 2 of 5
- CVE-2021-22729CRITICALCVSS 9.8EG 9.82021-07-21
A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all …
- CVE-2019-10881CRITICALCVSS 9.8EG 9.82021-04-13
Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded passwords which can be exploited and allow unauthorized access …
- CVE-2021-27440CRITICALCVSS 9.8EG 9.82021-03-25
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).
- CVE-2020-12047CRITICALCVSS 9.8EG 9.82020-06-29
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FTP service with hard-coded credentials.
- CVE-2020-12045CRITICALCVSS 9.8EG 9.82020-06-29
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a Telnet service on Port 1023 with hard-coded credentials.
- CVE-2020-12016CRITICALCVSS 9.8EG 9.82020-06-29
Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5, Baxter ExactaMix EM 2400 Versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1…
- CVE-2014-5434CRITICALCVSS 9.8EG 9.82019-03-26
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with hard-coded credentials used with the FTP protocol. Baxter asserts no files can be transferred to o…
- CVE-2015-3953CRITICALCVSS 9.8EG 9.82019-03-25
Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close …
- CVE-2017-6022CRITICALCVSS 9.8EG 9.82017-06-30
A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Service, Version 1.0.51 and prior versions. They use hard-coded passwords to access the BD Kies…
- CVE-2016-9358CRITICALCVSS 9.8EG 9.82017-06-30
A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Ca…
- CVE-2018-25069CRITICALCVSS 7.3EG 9.82023-01-07
A vulnerability classified as critical has been found in Netis Netcore Router. This affects an unknown part. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The identifier VDB-217593 wa…
- CVE-2014-125030CRITICALCVSS 6.3EG 9.82023-01-01
A vulnerability, which was classified as critical, has been found in taoeffect Empress. Affected by this issue is some unknown functionality. The manipulation leads to use of hard-coded password. The patch is identified as 557e177d8a309d6f…
- CVE-2021-28813CRITICALCVSS 9.6EG 9.62021-09-10
A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information b…
- CVE-2024-34539CRITICALCVSS 9.4EG 9.42024-06-14
Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also be used to login to the administration panel and to perform privileged ac…
- CVE-2023-23770CRITICALCVSS 9.4EG 9.42023-08-29
Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor passwor…
- CVE-2024-20412CRITICALCVSS 8.4EG 9.32024-10-23
A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerabil…
- CVE-2026-23933CRITICALCVSS 9.1EG 9.12026-08-18
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest u…
- CVE-2021-36312CRITICALCVSS 9.1EG 9.12021-11-23
Dell EMC CloudLink 7.1 and all prior versions contain a Hard-coded Password Vulnerability. A remote high privileged attacker, with the knowledge of the hard-coded credentials, may potentially exploit this vulnerability to gain unauthorized…
- CVE-2021-32525CRITICALCVSS 9.1EG 9.12021-07-07
The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restric…
- CVE-2024-2197CRITICALCVSS 4.3EG 9.12024-03-20
The Chirp Access app contains a hard-coded password, BEACON_PASSWORD. An attacker within Bluetooth range could change configuration settings within the Bluetooth beacon, effectively disabling the application's ability to notify users when …
- CVE-2014-5405HIGHCVSS v2 9.0EG 9.02015-04-03
Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.
- CVE-2026-65117HIGHCVSS 8.8EG 8.82026-09-22
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information dis…
- CVE-2026-22055HIGHCVSS 8.8EG 8.82026-06-03
Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.
- CVE-2026-22054HIGHCVSS 8.8EG 8.82026-06-03
Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.
- CVE-2026-4475HIGHCVSS 8.8EG 8.82026-03-20
A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The affected element is an unknown function of the file home/web/ipc. Such manipulation leads to hard-coded credentials. Access to the local network is …
- CVE-2025-14126HIGHCVSS 8.8EG 8.82025-12-06
A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the component Web Interface. Such manipulation leads to hard-coded credentials. The attack needs to be initiated within the …
- CVE-2025-9725HIGHCVSS 8.8EG 8.82025-08-31
A vulnerability was identified in Cudy LT500E up to 2.3.12. Affected is an unknown function of the file /squashfs-root/etc/shadow of the component Web Interface. The manipulation leads to use of hard-coded password. The attack must be carr…
- CVE-2025-44955HIGHCVSS 8.8EG 8.82025-08-04
RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.
- CVE-2025-30106HIGHCVSS 8.8EG 8.82025-03-18
On IROAD v9 devices, the dashcam has hardcoded default credentials ("qwertyuiop") that cannot be changed by the user. This allows an attacker within Wi-Fi range to connect to the device's network to perform sniffing.
- CVE-2024-37644HIGHCVSS 8.8EG 8.82024-06-14
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
- CVE-2024-35395HIGHCVSS 8.8EG 8.82024-05-24
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
- CVE-2024-34211HIGHCVSS 8.8EG 8.82024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
- CVE-2023-51629HIGHCVSS 8.8EG 8.82024-05-03
D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DCS-8300LHV2 IP cameras. Authentication is not r…
- CVE-2023-32145HIGHCVSS 8.8EG 8.82024-05-03
D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1360 routers. Authentication is not required t…
- CVE-2023-49963HIGHCVSS 8.8EG 8.82024-04-19
DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control.
- CVE-2024-28066HIGHCVSS 8.8EG 8.82024-04-08
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
- CVE-2022-27172HIGHCVSS 8.8EG 8.82022-05-12
A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can send a sequence of re…
- CVE-2021-27254HIGHCVSS 8.8EG 8.82021-03-05
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the apply_save.cgi endp…
- CVE-2025-2402HIGHCVSS 8.6EG 8.62025-03-31
A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in possession of the password to read and manipulate swapped jobs o…
- CVE-2025-3920HIGHCVSS 8.5EG 8.52025-07-07
A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These credentials correspond to a built-in administrative account of the software. An attacker with local access to the syst…
- CVE-2025-70802HIGHCVSS 8.4EG 8.42026-03-10
Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.
- CVE-2025-70798HIGHCVSS 8.4EG 8.42026-03-10
Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.
- CVE-2024-48831HIGHCVSS 8.4EG 8.42025-03-17
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
- CVE-2023-23771HIGHCVSS 8.4EG 8.42023-08-29
Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that can…
- CVE-2023-1944HIGHCVSS 8.4EG 8.42023-05-24
This vulnerability enables ssh access to minikube container using a default password.
- CVE-2025-46067HIGHCVSS 8.2EG 8.22026-01-12
An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file
- CVE-2026-71809HIGHCVSS 8.1EG 8.12026-09-09
Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.
- CVE-2026-19901HIGHCVSS 8.1EG 8.12026-08-15
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Atta…
- CVE-2026-19900HIGHCVSS 8.1EG 8.12026-08-15
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high …
- CVE-2026-19750HIGHCVSS 8.1EG 8.12026-08-13
A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to laun…
Map vulnerabilities like CWE-259 to your infrastructure
EchelonGraph correlates every CVE — across CWE-259 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →