CWE-321— Use of Hard-coded Cryptographic Key
The product uses a hard-coded, unchangeable cryptographic key.— MITRE CWE catalog
335 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-321page 4 of 7
- CVE-2024-54855MEDIUMCVSS 6.4EG 6.42026-01-13
fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts.
- CVE-2024-56429HIGHCVSS 7.7EG 7.72025-05-21
itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to the database.
- CVE-2024-5722HIGHCVSS 8.8EG 8.82024-11-22
Logsign Unified SecOps Platform HTTP API Hard-coded Cryptographic Key Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Logsign Unified SecOps P…
- CVE-2024-58134HIGHCVSS 8.1EG 8.12025-05-03
Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default. These predictable default secrets can be exploited by an attacker to forge session cookies…
- CVE-2024-6890CRITICALCVSS 8.8EG 9.82024-08-07
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.
- CVE-2025-10080LOWCVSS 3.1EG 3.12025-09-08
A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTokensecret of the file datart/security/src/main/java/datart/security/util/AESUtil.java of the component API. The manipula…
- CVE-2025-10250MEDIUMCVSS 5.0EG 5.02025-09-11
A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function of the component Telemetry Channel. Executing manipulation can lead to use of hard-coded cryptographic key . The attac…
- CVE-2025-1099HIGHCVSS 7.0EG 7.02025-02-10
This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can the…
- CVE-2025-11290MEDIUMCVSS 5.6EG 5.62025-10-05
A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of the argument secret with the input default leads to use of hard-coded cryptographic key .…
- CVE-2025-11609LOWCVSS 3.7EG 3.72025-10-11
A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-session. This manipulation of the argument secret with the input secret causes use of hard-coded cryptographic…
- CVE-2025-11781HIGHCVSS 7.8EG 7.82025-12-02
Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the fi…
- CVE-2025-11899HIGHCVSS 8.1EG 8.12025-10-17
Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information, thereby logging into the system as any user.…
- CVE-2025-12177MEDIUMCVSS 5.3EG 5.32025-11-08
The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible…
- CVE-2025-12599CRITICALCVSS 9.8EG 9.82025-11-01
Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2025-12615MEDIUMCVSS 5.0EG 5.02025-11-03
A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key …
- CVE-2025-13316HIGHCVSS 8.1EG 8.12025-11-19
Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the pla…
- CVE-2025-13877MEDIUMCVSS 5.6EG 5.62025-12-02
A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argument…
- CVE-2025-13948MEDIUMCVSS 5.6EG 5.62025-12-03
A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the file docs/docker-compose/docker-compose.yaml of the component JWT Handler. Executing manipulation of the argument secre…
- CVE-2025-14651LOWCVSS 3.7EG 3.72025-12-14
A vulnerability has been found in MartialBE one-hub up to 0.14.27. This vulnerability affects unknown code of the file docker-compose.yml. The manipulation of the argument SESSION_SECRET leads to use of hard-coded cryptographic key . The …
- CVE-2025-14923CRITICALCVSS 9.8EG 9.82026-03-03
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
- CVE-2025-15005LOWCVSS 3.7EG 3.72025-12-22
A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.example.php of the component reCAPTCHA Handler. The manipulation of the argument K_RECAPTCHA_SITE_KEY/K_RECAPTCHA_SECRET_KE…
- CVE-2025-15016CRITICALCVSS 9.8EG 9.82025-12-22
Enterprise Cloud Database developed by Ragic has a Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information and log into the system as any user.
- CVE-2025-15105LOWCVSS 3.7EG 3.72025-12-27
A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxun/maxun/blob/develop/server/src/routes/auth.ts. Performing manipulation of the argument api_key results in use of hard-…
- CVE-2025-15107LOWCVSS 3.7EG 3.72025-12-27
A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown function of the file sqle/utils/jwt.go of the component JWT Secret Handler. The manipulation of the argument JWTSecretKey lead…
- CVE-2025-15108LOWCVSS 3.7EG 3.72025-12-27
A vulnerability was detected in PandaXGO PandaX up to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5. This affects an unknown function of the file config.yml of the component JWT Secret Handler. The manipulation of the argument key results in us…
- CVE-2025-15605HIGHCVSS 7.3EG 7.32026-03-23
A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, …
- CVE-2025-15627HIGHCVSS 7.5EG 7.52026-08-03
A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. …
- CVE-2025-22455HIGHCVSS 8.8EG 8.82025-06-10
A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials.
- CVE-2025-22463HIGHCVSS 7.3EG 7.32025-06-10
A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password.
- CVE-2025-24525HIGHCVSS 7.5EG 7.52025-09-30
Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the TLS certif…
- CVE-2025-26340HIGHCVSS 8.8EG 8.82025-02-12
A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to bypass the authentication via crafted HTTP requests.
- CVE-2025-26476HIGHCVSS 8.4EG 8.42025-08-04
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthoriz…
- CVE-2025-27674CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Hardcoded IdP Key V-2023-006.
- CVE-2025-2810MEDIUMCVSS 5.5EG 5.52025-08-05
A low privileged local attacker can abuse the affected service by using a hardcoded cryptographic key.
- CVE-2025-30095CRITICALCVSS 9.0EG 9.02025-03-31
VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle a…
- CVE-2025-30198MEDIUMCVSS 6.3EG 6.32025-09-05
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.
- CVE-2025-30200MEDIUMCVSS 6.3EG 6.32025-09-05
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.
- CVE-2025-30206CRITICALCVSS 9.8EG 9.82025-04-15
Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration, allowing attackers to generate valid JWT tokens and comprom…
- CVE-2025-30234HIGHCVSS 8.3EG 8.32025-03-19
SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a Debian 12 LX zone image from 2024-07-26).
- CVE-2025-30239HIGHCVSS 8.5EG 8.52026-08-10
In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. …
- CVE-2025-30406CRITICALCVSS 9.0EG 9.0⚠ KEV2025-04-03
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who…
- CVE-2025-31362LOWCVSS 3.7EG 3.72025-04-11
Use of hard-coded cryptographic key issue exists in BizRobo! all versions. Credentials inside robot files may be obtained if the encryption key is available. The vendor provides the workaround information and recommends to apply it to the…
- CVE-2025-3177MEDIUMCVSS 5.0EG 5.02025-04-03
A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack can be initiate…
- CVE-2025-32730MEDIUMCVSS 5.5EG 5.52025-04-24
Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentica…
- CVE-2025-34211MEDIUMCVSS 4.9EG 4.92025-09-29
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA and SaaS deployments) contain a private SSL key and matching public certificate stored in cleartext. The…
- CVE-2025-34215CRITICALCVSS 9.8EG 9.82025-09-29
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (only VA deployments) expose an unauthenticated firmware-upload flow: a public page returns a signed token us…
- CVE-2025-34217CRITICALCVSS 9.8EG 9.82025-09-30
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumented 'printerlogic' user with a hardcoded SSH public key in '~/.ssh/authorized_keys' and a sudoers rule granting the print…
- CVE-2025-34234HIGHCVSS 7.5EG 7.52025-09-29
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain two hardcoded private keys that are shipped in the application containers (print…
- CVE-2025-34256CRITICALCVSS 9.8EG 9.82025-12-05
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs th…
- CVE-2025-34500HIGHCVSS 7.0EG 7.02025-10-24
Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses a truncated HMAC for integrity validation. Attackers with…
Map vulnerabilities like CWE-321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →