CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,818 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 2 of 37
- CVE-2015-7246CRITICALCVSS 9.8EG 9.82017-04-24
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative access.
- CVE-2015-7276MEDIUMCVSS 5.9EG 5.92019-11-06
Technicolor C2000T and C2100T uses hard-coded cryptographic keys.
- CVE-2015-9254CRITICALCVSS 9.8EG 9.82018-02-20
Datto ALTO and SIRIS devices have a default VNC password.
- CVE-2016-0235HIGHCVSS 8.2EG 8.22018-03-12
IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB systems. IBM X-Force ID: 110326.
- CVE-2016-0726CRITICALCVSS 9.8EG 9.82017-06-06
The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.
- CVE-2016-10115CRITICALCVSS 9.8EG 9.82017-01-04
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier f…
- CVE-2016-10125HIGHCVSS 8.1EG 8.12017-01-09
D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session.
- CVE-2016-10177CRITICALCVSS 9.8EG 9.82017-01-30
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.
- CVE-2016-10179HIGHCVSS 7.5EG 7.52017-01-30
An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.
- CVE-2016-10305CRITICALCVSS 9.8EG 9.82017-03-30
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, wi…
- CVE-2016-10306CRITICALCVSS 9.8EG 9.82017-03-30
Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full contr…
- CVE-2016-10307CRITICALCVSS 9.8EG 9.82017-03-30
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet pu…
- CVE-2016-10308CRITICALCVSS 9.8EG 9.82017-03-30
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and gr…
- CVE-2016-10928HIGHCVSS 7.5EG 7.52019-08-22
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
- CVE-2016-1560CRITICALCVSS 9.8EG 9.82017-04-21
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative acces…
- CVE-2016-20026CRITICALCVSS 9.8EG 9.82026-03-16
ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-user…
- CVE-2016-20031MEDIUMCVSS 5.5EG 5.52026-03-16
ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid credentials by spoofing localhost requests. Attackers can exploit the EnvironmentUtil.getClien…
- CVE-2016-2310CRITICALCVSS 9.8EG 9.82016-06-09
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify co…
- CVE-2016-2357CRITICALCVSS 9.8EG 9.82019-10-25
Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.
- CVE-2016-2358CRITICALCVSS 9.8EG 9.82019-10-25
Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are accessible if the customer has not configured 10 actual user accounts.
- CVE-2016-2360CRITICALCVSS 9.8EG 9.82019-10-25
Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations.
- CVE-2016-2948HIGHCVSS 7.8EG 7.82016-11-30
IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.
- CVE-2016-3685MEDIUMCVSS 4.7EG 4.72016-12-14
SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of a har…
- CVE-2016-3953CRITICALCVSS 9.8EG 9.82018-02-06
The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a hardcoded encryption key when calling the session.connect function.
- CVE-2016-5081CRITICALCVSS 9.8EG 9.82016-08-24
ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET session.
- CVE-2016-5333CRITICALCVSS 9.8EG 9.82016-08-31
VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
- CVE-2016-5645HIGHCVSS 7.3EG 7.32016-08-24
Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote attackers to load arbitrary firmware upda…
- CVE-2016-5678CRITICALCVSS 9.8EG 9.82016-08-31
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.
- CVE-2016-5816HIGHCVSS 7.5EG 7.52017-08-25
A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded private cryptographic keys that may allow an a…
- CVE-2016-5818CRITICALCVSS 9.8EG 9.82017-02-13
An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the device.
- CVE-2016-6530CRITICALCVSS 9.8EG 9.82016-09-21
Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain administrative access by leveraging knowledge of these passwords.
- CVE-2016-6532CRITICALCVSS 9.8EG 9.82016-09-24
DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this password in a DEXIS_DATA SQL Server session.
- CVE-2016-6535CRITICALCVSS 9.8EG 9.82016-09-19
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishing a TELNET session.
- CVE-2016-6829CRITICALCVSS 9.8EG 9.82016-12-09
The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for remote attackers t…
- CVE-2016-7560CRITICALCVSS 9.8EG 9.82016-10-05
The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remote attackers to read or write to arbitrary files via unspecified vectors.
- CVE-2016-8361HIGHCVSS 8.6EG 8.62017-02-13
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication.
- CVE-2016-8491CRITICALCVSS 9.1EG 9.12017-02-01
The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.
- CVE-2016-8567CRITICALCVSS 9.8EG 9.82017-02-13
An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Attackers might gain privileged access to the database over Port 2638/TCP.
- CVE-2016-8717CRITICALCVSS 9.8EG 9.82018-04-02
An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with hard-coded credentials…
- CVE-2016-8731CRITICALCVSS 9.8EG 9.82017-06-21
Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked by an intermediate …
- CVE-2016-8754HIGHCVSS 7.5EG 7.52017-04-02
Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys are used to encrypt communication data and authenticate different nodes of the devices. An attacker may obtain the hardcoded keys and log in to …
- CVE-2016-8954CRITICALCVSS 9.8EG 9.82017-02-08
IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.
- CVE-2016-9013CRITICALCVSS 9.8EG 9.82016-12-09
Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain acces…
- CVE-2016-9335CRITICALCVSS 10.0EG 10.02018-05-09
A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 and Stride-Managed Ethernet Switches running firmware Version 5.0.190. Vulnerable versions…
- CVE-2016-9358CRITICALCVSS 9.8EG 9.82017-06-30
A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Ca…
- CVE-2016-9495HIGHCVSS 8.8EG 8.82018-07-13
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default telnet port (23) can be obtained through using one of a few default credentials shared among …
- CVE-2017-10616MEDIUMCVSS 5.3EG 6.52017-10-13
The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-20…
- CVE-2017-10818CRITICALCVSS 9.8EG 9.82017-08-04
MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection settings of Terminal Agent and spoof the Relay Service.
- CVE-2017-11026HIGHCVSS 7.8EG 7.82017-11-16
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing FRP partition using reference FRP unlock, authentication method can be compromised for static keys.
- CVE-2017-11129CRITICALCVSS 9.8EG 9.82017-08-01
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The keystore is locked with a hard-coded password. Therefore, everyone with access to the keystore can read the content out, for example the private key of the u…
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →