CWE-321— Use of Hard-coded Cryptographic Key
The product uses a hard-coded, unchangeable cryptographic key.— MITRE CWE catalog
381 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-321page 2 of 8
- CVE-2023-42492CRITICALCVSS 9.8EG 9.82023-10-25
EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key
- CVE-2023-3632CRITICALCVSS 9.8EG 9.82023-08-09
Use of Hard-coded Cryptographic Key vulnerability in Sifir Bes Education and Informatics Kunduz - Homework Helper App allows Authentication Abuse, Authentication Bypass. This issue affects Kunduz - Homework Helper App: before 6.2.3.
- CVE-2023-2158CRITICALCVSS 9.8EG 9.82023-04-27
Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-cod…
- CVE-2023-27583CRITICALCVSS 9.8EG 9.82023-03-13
PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user with admin privileges.…
- CVE-2022-2660CRITICALCVSS 9.8EG 9.82022-12-13
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.
- CVE-2022-2641CRITICALCVSS 9.8EG 9.82022-12-02
Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an attacker to perform unauthorized changes to the device, remotely execute arbitrary code, or cause a denial-of-service …
- CVE-2022-0664CRITICALCVSS 9.8EG 9.82022-02-18
Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.
- CVE-2022-22987CRITICALCVSS 9.8EG 9.82022-02-04
The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions.
- CVE-2021-40119CRITICALCVSS 9.8EG 9.82021-11-04
A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-use of static SSH key…
- CVE-2021-32520CRITICALCVSS 9.8EG 9.82021-07-07
Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
- CVE-2021-27389CRITICALCVSS 9.8EG 9.82021-04-22
A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30). A private sign key is shipped with the product without adequate protection.
- CVE-2020-2500CRITICALCVSS 9.8EG 9.82020-07-01
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulner…
- CVE-2020-6990CRITICALCVSS 9.8EG 9.82020-03-16
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the accoun…
- CVE-2019-19750CRITICALCVSS 9.8EG 9.82019-12-12
minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.
- CVE-2018-0040CRITICALCVSS 9.8EG 9.82018-07-11
Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized access to services.
- CVE-2017-14021CRITICALCVSS 9.8EG 9.82017-11-01
A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4…
- CVE-2017-7574CRITICALCVSS 9.8EG 9.82017-04-06
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected pro…
- CVE-2026-26335CRITICALCVSS 9.3EG 9.82026-02-13
Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Program Files (x86)\\Veramark\\VeraSMART\\WebRoot\\web.config. An attacker who obtains thes…
- CVE-2024-6890CRITICALCVSS 8.8EG 9.82024-08-07
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.
- CVE-2022-34440CRITICALCVSS 8.4EG 9.82023-01-11
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerabilit…
- CVE-2021-0266CRITICALCVSS 8.1EG 9.82021-04-22
The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper …
- CVE-2022-34442CRITICALCVSS 8.0EG 9.82023-01-18
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerabi…
- CVE-2022-34441CRITICALCVSS 8.0EG 9.82023-01-11
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerabili…
- CVE-2021-22644CRITICALCVSS 7.5EG 9.82022-07-28
Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.
- CVE-2022-1400CRITICALCVSS 7.1EG 9.82022-08-17
Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device4…
- CVE-2025-45746CRITICALCVSS 6.5EG 9.82025-05-13
In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is t…
- CVE-2026-85153CRITICALCVSS 9.3EG 9.32026-10-06
This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed appl…
- CVE-2026-71449CRITICALCVSS 9.3EG 9.32026-10-01
: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.
- CVE-2026-46395CRITICALCVSS 9.3EG 9.32026-05-19
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementation errors that together allow any unaut…
- CVE-2026-81855CRITICALCVSS 9.1EG 9.12026-09-15
A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.
- CVE-2026-53939CRITICALCVSS 9.1EG 9.12026-09-08
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384…
- CVE-2026-75431CRITICALCVSS 9.1EG 9.12026-09-04
PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.
- CVE-2026-51977CRITICALCVSS 9.1EG 9.12026-08-17
An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component
- CVE-2026-14804CRITICALCVSS 9.1EG 9.12026-08-04
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resource…
- CVE-2026-18754CRITICALCVSS 9.1EG 9.12026-08-04
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communicat…
- CVE-2026-18753CRITICALCVSS 9.1EG 9.12026-08-04
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communicat…
- CVE-2026-54363CRITICALCVSS 9.1EG 9.12026-07-30
CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and Ac…
- CVE-2026-62241CRITICALCVSS 9.1EG 9.12026-07-17
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing user…
- CVE-2026-31986CRITICALCVSS 9.1EG 9.12026-05-19
Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
- CVE-2026-5426CRITICALCVSS 9.1EG 9.12026-04-16
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState…
- CVE-2025-63289CRITICALCVSS 9.1EG 9.12025-11-12
Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encryption_helper.dart file
- CVE-2019-19753CRITICALCVSS 9.1EG 9.12024-04-30
SimpleMiningOS through v1259 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: the vendor indicated that they …
- CVE-2024-1631CRITICALCVSS 9.1EG 9.12024-02-21
Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which will then be used as the secret key. When no seed value is provided, it is …
- CVE-2022-29830CRITICALCVSS 9.1EG 9.12022-11-25
Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.065T allows a remote unauthenticated attack…
- CVE-2022-29186CRITICALCVSS 9.1EG 9.12022-05-20
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated SSH keypair. If the id_rsa.pub public key of the keypair was…
- CVE-2026-50091CRITICALCVSS 7.4EG 9.12026-06-12
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimat…
- CVE-2019-7594CRITICALCVSS 6.8EG 9.12019-08-20
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).
- CVE-2026-78225CRITICALCVSS 9.0EG 9.02026-09-15
A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
- CVE-2025-44963CRITICALCVSS 9.0EG 9.02025-08-04
RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
- CVE-2025-30095CRITICALCVSS 9.0EG 9.02025-03-31
VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle a…
Map vulnerabilities like CWE-321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →