CWE-259— Use of Hard-coded Password
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.— MITRE CWE catalog
216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-259page 5 of 5
- CVE-2024-11026LOWCVSS 3.7EG 3.72024-11-08
A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ch/qos/logback/core/net/ssl/SSL.java of the component Keystore…
- CVE-2024-7170LOWCVSS 3.5EG 3.52024-07-28
A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini. The manipulation leads to use of hard-coded password. The expl…
- CVE-2023-28895LOWCVSS 3.5EG 3.52023-12-01
The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The console allows attackers with physical access to the MIB3 unit to gain full control over the PW…
- CVE-2026-4993LOWCVSS 3.3EG 3.32026-03-28
A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/openui/config.py. The manipulation of the argument LITELLM_MASTER_KEY leads to hard-coded credentials. An attack has to …
- CVE-2026-4219LOWCVSS 3.3EG 3.32026-03-16
A flaw has been found in INDEX Conferences & Exhibitions Organization YWF BPOF APGCS App up to 1.0.2 on Android. Affected by this vulnerability is an unknown functionality of the file com/index/event/BuildConfig.java of the component ae.in…
- CVE-2026-2702LOWCVSS 3.1EG 3.12026-02-19
A security flaw has been discovered in Beetel 777VR1 up to 01.00.09. This issue affects some unknown processing of the component WPA2 PSK. Performing a manipulation results in hard-coded credentials. The attacker must have access to the lo…
- CVE-2025-2555LOWCVSS 2.9EG 2.92025-03-20
A vulnerability classified as problematic has been found in Audi Universal Traffic Recorder App 2.0. Affected is an unknown function of the component FTP Credentials. The manipulation leads to use of hard-coded password. Attacking locally …
- CVE-2024-7216LOWCVSS 2.6EG 2.62024-07-30
A vulnerability was found in TOTOLINK LR1200 9.3.1cu.2832. It has been classified as problematic. This affects an unknown part of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The complexity of an attac…
- CVE-2025-36609LOWCVSS 2.5EG 2.52025-07-30
Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
- CVE-2024-7155LOWCVSS 2.5EG 2.52024-07-28
A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/shadow.sample. The manipulation leads to use of hard-coded …
- CVE-2025-1879LOWCVSS 2.4EG 2.42025-03-03
A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some unknown processing of the component APK. The manipulation leads to hard-coded credentials. It is possible to launch the …
- CVE-2020-12039LOWCVSS 2.4EG 2.42020-06-29
Baxter Sigma Spectrum Infusion Pumps Sigma Spectrum Infusion System v's6.x model 35700BAX & Baxter Spectrum Infusion System v's8.x model 35700BAX2 contain hardcoded passwords when physically entered on the keypad provide access to biomedic…
- CVE-2025-47823LOWCVSS 2.2EG 2.22025-06-27
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system.
- CVE-2025-47821LOWCVSS 2.2EG 2.22025-06-27
Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system.
- CVE-2025-47818LOWCVSS 2.2EG 2.22025-06-27
Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.
- CVE-2025-7741LOWCVSS 2.1EG 2.12026-03-30
Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk …
Map vulnerabilities like CWE-259 to your infrastructure
EchelonGraph correlates every CVE — across CWE-259 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →