CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 4 of 39
- CVE-2025-33222CRITICALCVSS 9.8EG 9.82025-12-23
NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and data …
- CVE-2025-67418CRITICALCVSS 9.8EG 9.82025-12-22
ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remote attacker can log in to the administrative panel using th…
- CVE-2025-56157CRITICALCVSS 9.8EG 9.82025-12-18
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port …
- CVE-2025-7358CRITICALCVSS 9.8EG 9.82025-12-18
Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse. This issue affects SoliClub: before 5.3.7.
- CVE-2025-36752CRITICALCVSS 9.8EG 9.82025-12-13
Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that …
- CVE-2025-36747CRITICALCVSS 9.8EG 9.82025-12-13
ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to…
- CVE-2025-54947CRITICALCVSS 9.8EG 9.82025-12-12
In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically genera…
- CVE-2025-65823CRITICALCVSS 9.8EG 9.82025-12-10
The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi network, they could gain unaut…
- CVE-2025-40938CRITICALCVSS 9.8EG 9.82025-12-09
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the…
- CVE-2025-29268CRITICALCVSS 9.8EG 9.82025-12-04
ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.
- CVE-2025-10850CRITICALCVSS 9.8EG 9.82025-10-16
The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password in the 'fb_ajax_login_or_register' function and in the 'google_ajax_login_or_r…
- CVE-2025-34223CRITICALCVSS 9.8EG 9.82025-09-29
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) contain a default admin account and an installation‑time endpoint at `/admin/quer…
- CVE-2025-34196CRITICALCVSS 9.8EG 9.82025-09-29
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments) contain a hardcoded private key for the PrinterLogic Certificate Authority (CA) and a ha…
- CVE-2025-11126CRITICALCVSS 9.8EG 9.82025-09-29
A security flaw has been discovered in Apeman ID71 218.53.203.117. This vulnerability affects unknown code of the file /system/www/system.ini. The manipulation results in hard-coded credentials. The attack may be performed from remote. The…
- CVE-2025-57602CRITICALCVSS 9.8EG 9.82025-09-22
Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH private key, allows remote attackers to authenticate to the cloud controller, gain interactive shell ac…
- CVE-2025-57601CRITICALCVSS 9.8EG 9.82025-09-22
AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access to all managed IoT/edge devices. When an administrator initiates "Open Remote Terminal" from the AiKaan dashboard, the …
- CVE-2025-34198CRITICALCVSS 9.8EG 9.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951 and Application prior to 20.0.2368 (VA and SaaS deployments) contain shared, hardcoded SSH host private keys in the appliance image. The same private ho…
- CVE-2025-8570CRITICALCVSS 9.8EG 9.82025-09-11
The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 3.0.1. This makes it possible fo…
- CVE-2025-35452CRITICALCVSS 9.8EG 9.82025-09-05
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.
- CVE-2025-35451CRITICALCVSS 9.8EG 9.82025-09-05
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be…
- CVE-2025-8857CRITICALCVSS 9.8EG 9.82025-08-29
Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to log into the system using administrator credentials embedded in the source code.
- CVE-2025-8974CRITICALCVSS 9.8EG 9.82025-08-14
A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/util/JwtHelper.java of the component JSON Web Toke…
- CVE-2025-43982CRITICALCVSS 9.8EG 9.82025-08-13
Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden hard-coded root account that cannot be disabled in the GUI.
- CVE-2025-8730CRITICALCVSS 9.8EG 9.82025-08-08
A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to hard-coded credentials. The …
- CVE-2025-51536CRITICALCVSS 9.8EG 9.82025-08-04
Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.
- CVE-2025-30125CRITICALCVSS 9.8EG 9.82025-07-28
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an insecure-by-default condition. For users who change their passwords, it's limited …
- CVE-2025-52376CRITICALCVSS 9.8EG 9.82025-07-15
An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotely enable the Telnet service without authentication, bypassin…
- CVE-2025-7401CRITICALCVSS 9.8EG 9.82025-07-11
The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versi…
- CVE-2025-37103CRITICALCVSS 9.8EG 9.82025-07-08
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrativ…
- CVE-2025-45813CRITICALCVSS 9.8EG 9.82025-07-02
ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.
- CVE-2025-45784CRITICALCVSS 9.8EG 9.82025-06-18
D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user credentials. An attacker with access to the firmware image can extract these credentials using s…
- CVE-2025-28388CRITICALCVSS 9.8EG 9.82025-06-13
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
- CVE-2025-46352CRITICALCVSS 9.8EG 9.82025-05-30
The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string in the binary responsible for running VNC. This password cannot be altered, allowing anyone with knowledge of it to ga…
- CVE-2025-32985CRITICALCVSS 9.8EG 9.82025-04-25
NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.
- CVE-2025-46274CRITICALCVSS 9.8EG 9.82025-04-24
UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed database.
- CVE-2025-46273CRITICALCVSS 9.8EG 9.82025-04-24
UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devices.
- CVE-2025-2538CRITICALCVSS 9.8EG 9.82025-03-20
A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated attacker to gain administrative access to the system.
- CVE-2025-30137CRITICALCVSS 9.8EG 9.82025-03-18
An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for ports 9091 and 9092. The GNET mobile application contains hardcoded credentials that provide unauthorized access to the dashcam's API endpoints …
- CVE-2025-30123CRITICALCVSS 9.8EG 9.82025-03-18
An issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the FTPX user account, enabling attackers to gain unauthorized access and extract sensitive recorded footage from the device.
- CVE-2025-30122CRITICALCVSS 9.8EG 9.82025-03-18
An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for attackers to gain unauthorized access to multiple devices.
- CVE-2025-30113CRITICALCVSS 9.8EG 9.82025-03-18
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashcam's Android application contains hardcoded credentials that allow unauthorized access to d…
- CVE-2025-1393CRITICALCVSS 9.8EG 9.82025-03-05
An unauthenticated remote attacker can use hard-coded credentials to gain full administration privileges on the affected product.
- CVE-2025-27643CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Hardcoded AWS API Key V-2024-006.
- CVE-2025-25570CRITICALCVSS 9.8EG 9.82025-02-27
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.
- CVE-2024-57040CRITICALCVSS 9.8EG 9.82025-02-26
TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained by analyzing downloaded firmware or via a brute force att…
- CVE-2024-50688CRITICALCVSS 9.8EG 9.82025-02-26
SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry.
- CVE-2025-26410CRITICALCVSS 9.8EG 9.82025-02-11
The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via …
- CVE-2024-51547CRITICALCVSS 9.8EG 9.82025-02-06
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
- CVE-2024-9643CRITICALCVSS 9.8EG 9.82025-02-04
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via craf…
- CVE-2024-53356CRITICALCVSS 9.8EG 9.82025-01-31
Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for generating tokens is hardcoded as "somerandomaccesstoken". A weak …
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →