CWE-259— Use of Hard-coded Password
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.— MITRE CWE catalog
216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-259page 4 of 5
- CVE-2025-9731HIGHCVSS 7.0EG 7.02025-08-31
A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation causes hard-coded credentials. It is possible to l…
- CVE-2025-9309HIGHCVSS 7.0EG 7.02025-08-21
A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the component MD5 Hash Handler. Performing manipulation results in hard-coded credentials. The attack needs to be approached…
- CVE-2025-57175MEDIUMCVSS 6.8EG 6.82026-04-08
Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password.
- CVE-2025-8231MEDIUMCVSS 6.8EG 6.82025-07-27
A vulnerability, which was classified as critical, has been found in D-Link DIR-890L up to 111b04. This issue affects some unknown processing of the file rgbin of the component UART Port. The manipulation leads to hard-coded credentials. I…
- CVE-2025-25984MEDIUMCVSS 6.8EG 6.82025-04-18
An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via UART component.
- CVE-2024-31798MEDIUMCVSS 6.8EG 6.82024-08-15
Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices
- CVE-2020-7590MEDIUMCVSS 6.8EG 6.82020-10-13
A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Affected devices use a hard-c…
- CVE-2014-5431MEDIUMCVSS 6.8EG 6.82019-03-26
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contains a hard-coded password, which provides access to basic biomedical information, limited device settings, and network c…
- CVE-2018-8870MEDIUMCVSS 6.4EG 6.82018-07-03
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can remove the case of the device, connect to the debug port, and use the password to gain pr…
- CVE-2023-0808MEDIUMCVSS 3.9EG 6.82023-02-13
A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects some unknown processing of the component Access Point Setting Handler. The manipulation w…
- CVE-2025-11666MEDIUMCVSS 6.7EG 6.72025-10-13
A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to us…
- CVE-2025-61330MEDIUMCVSS 6.5EG 6.52025-10-16
A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment manufacturer H3C. The vulnerability stems from the use of a hard-coded weak password for the root account in the /etc/…
- CVE-2025-57788MEDIUMCVSS 6.5EG 6.52025-08-20
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.
- CVE-2025-28031MEDIUMCVSS 6.5EG 6.52025-04-22
TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.ini.
- CVE-2024-46959MEDIUMCVSS 6.5EG 6.52024-09-18
runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows access to the /stream1 URI via the rtsp:// protocol to receive the video and audio stream.
- CVE-2025-9806MEDIUMCVSS 6.4EG 6.42025-09-02
A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded cred…
- CVE-2022-26388MEDIUMCVSS 6.4EG 6.42025-02-07
A use of hard-coded password vulnerability may allow authentication abuse.This issue affects ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior; ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph: Versions 2.3.1 and prior; EL…
- CVE-2026-105141MEDIUMCVSS 6.3EG 6.32026-10-04
A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handl…
- CVE-2023-3237MEDIUMCVSS 6.3EG 6.32023-06-14
A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input admin leads to use of hard-coded password. The exploit has bee…
- CVE-2023-2799MEDIUMCVSS 6.3EG 6.32023-05-18
A vulnerability, which was classified as problematic, has been found in cnoa OA up to 5.1.1.5. Affected by this issue is some unknown functionality of the file /index.php?app=main&func=passport&action=login. The manipulation leads to use o…
- CVE-2020-2499MEDIUMCVSS 6.3EG 6.32020-12-24
A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200…
- CVE-2023-2061MEDIUMCVSS 6.2EG 6.22023-06-02
Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to o…
- CVE-2020-12012MEDIUMCVSS 6.1EG 6.12020-06-29
Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5, Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13, and ExactaMix EM1200 Versions 1.1, 1.2, an…
- CVE-2024-28023MEDIUMCVSS 5.7EG 5.72024-06-11
A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary cod…
- CVE-2026-70413MEDIUMCVSS 5.6EG 5.62026-09-28
Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
- CVE-2026-96548MEDIUMCVSS 5.6EG 5.62026-09-23
A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is possib…
- CVE-2026-6578MEDIUMCVSS 5.6EG 5.62026-04-19
A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component Setting Handler. The manipulation of the argument SECRET_KEY results in hard…
- CVE-2024-7159MEDIUMCVSS 5.5EG 5.52024-07-28
A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been rated as critical. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation lead…
- CVE-2024-21990MEDIUMCVSS 5.4EG 5.42024-04-17
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentials.
- CVE-2026-11552MEDIUMCVSS 5.3EG 5.32026-06-08
A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue is some unknown functionality of the file import_us…
- CVE-2026-11515MEDIUMCVSS 5.3EG 5.32026-06-08
A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passsword_reset.php of the component Password Reset Handler. Such m…
- CVE-2026-4216MEDIUMCVSS 5.3EG 5.32026-03-16
A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the component air.SmartLog.android. This manipulation causes hard-coded credentials. The attack can only be executed locally.…
- CVE-2025-12676MEDIUMCVSS 5.3EG 5.32025-11-05
The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5. This is due to the plugin using a hardcoded password for authentication in the QueryControllerAdmin::authenticated fu…
- CVE-2025-47748MEDIUMCVSS 5.3EG 5.32025-05-28
Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.
- CVE-2025-2342MEDIUMCVSS 5.3EG 5.32025-03-16
A vulnerability classified as critical has been found in IROAD X5 Mobile App up to 5.2.5 on Android. Affected is an unknown function of the component API Endpoint. The manipulation leads to hard-coded credentials. It is possible to launch …
- CVE-2024-32210MEDIUMCVSS 5.3EG 5.32024-05-01
The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default for forms and SQL connections.
- CVE-2017-6039MEDIUMCVSS 5.3EG 5.32017-06-02
A Use of Hard-Coded Password issue was discovered in Phoenix Broadband PowerAgent SC3 BMS, all versions prior to v6.87. Use of a hard-coded password may allow unauthorized access to the device.
- CVE-2024-33867MEDIUMCVSS 4.8EG 4.82024-05-14
An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.
- CVE-2025-5379MEDIUMCVSS 4.3EG 4.32025-05-31
A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects unknown code of the component Console Application. The manipulation of the argument CMCCAdmin/useradmin/CUAdmin leads …
- CVE-2025-2556MEDIUMCVSS 4.3EG 4.32025-03-20
A vulnerability classified as problematic was found in Audi UTR Dashcam 2.0. Affected by this vulnerability is an unknown functionality of the component Video Stream Handler. The manipulation leads to hard-coded credentials. The attack can…
- CVE-2024-26196MEDIUMCVSS 4.3EG 4.32024-03-21
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
- CVE-2023-29103MEDIUMCVSS 4.3EG 4.32023-05-09
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC712 (All versions < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 C…
- CVE-2026-86150MEDIUMCVSS 4.1EG 4.12026-09-05
A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be l…
- CVE-2025-6139LOWCVSS 3.9EG 3.92025-06-16
A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issue is some unknown functionality of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. T…
- CVE-2026-6610LOWCVSS 3.7EG 3.72026-04-20
A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Handler. Such manipulation of the argument USER/PASSWORD leads…
- CVE-2025-11643LOWCVSS 3.7EG 3.72025-10-12
A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. Affected by this vulnerability is an unknown functionality of the file /squashfs-root/furbo_img of the component MQTT Client Certificate. Performing manipulation resu…
- CVE-2025-7577LOWCVSS 3.7EG 3.72025-07-14
A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been classified as problematic. This affects an unknown part. The manipulation leads to use of hard-coded password. It is possible to initiate th…
- CVE-2025-7453LOWCVSS 3.7EG 3.72025-07-11
A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects the function NewToken of the file zpan/internal/app/service/token.go of the component JSON Web Token Handler. The manipu…
- CVE-2025-7080LOWCVSS 3.7EG 3.72025-07-06
A vulnerability, which was classified as problematic, was found in Done-0 Jank up to 322caebbad10568460364b9667aa62c3080bfc17. Affected is an unknown function of the file internal/utils/jwt_utils.go of the component JWT Token Handler. The …
- CVE-2025-6932LOWCVSS 3.7EG 3.72025-06-30
A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the function g_F_n_GenPassForQlync of the file /bin/httpd of the component Qlync Password Generation Handler. The manipulation le…
Map vulnerabilities like CWE-259 to your infrastructure
EchelonGraph correlates every CVE — across CWE-259 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →