CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 5 of 39
- CVE-2024-48126CRITICALCVSS 9.8EG 9.82025-01-15
HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access.
- CVE-2023-37936CRITICALCVSS 9.8EG 9.82025-01-14
A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized co…
- CVE-2024-4996CRITICALCVSS 9.8EG 9.82024-12-18
Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERP installations…
- CVE-2024-55557CRITICALCVSS 9.8EG 9.82024-12-16
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.
- CVE-2024-54750CRITICALCVSS 9.8EG 9.82024-12-06
Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: In Ubiquiti's view there is no vulnerability as the Hardcoded Password should be after setup…
- CVE-2023-51638CRITICALCVSS 9.8EG 9.82024-11-22
Allegra Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. T…
- CVE-2024-52295CRITICALCVSS 9.8EG 9.82024-11-13
DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and take over services. The JWT secret is hardcoded in the code, and the UID and OID are hardcoded. The vulnerability has …
- CVE-2024-51431CRITICALCVSS 9.8EG 9.82024-11-01
LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.
- CVE-2024-45656CRITICALCVSS 9.8EG 9.82024-10-29
IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to ga…
- CVE-2024-48539CRITICALCVSS 9.8EG 9.82024-10-24
Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.
- CVE-2024-9486CRITICALCVSS 9.8EG 9.82024-10-15
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default …
- CVE-2024-45275CRITICALCVSS 9.8EG 9.82024-10-15
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
- CVE-2024-43423CRITICALCVSS 9.8EG 9.82024-09-25
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.
- CVE-2023-27584CRITICALCVSS 9.8EG 9.82024-09-19
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key …
- CVE-2024-45698CRITICALCVSS 9.8EG 9.82024-09-16
Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can the…
- CVE-2024-6656CRITICALCVSS 9.8EG 9.82024-09-13
Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Within an Executable. This issue affects Cockpit Software: before v2.13.
- CVE-2024-6633CRITICALCVSS 9.8EG 9.82024-08-27
The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability o…
- CVE-2024-8162CRITICALCVSS 9.8EG 9.82024-08-26
A vulnerability classified as critical has been found in TOTOLINK T10 AC1200 4.1.8cu.5207. Affected is an unknown function of the file /squashfs-root/web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to h…
- CVE-2024-42638CRITICALCVSS 9.8EG 9.82024-08-16
H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- CVE-2024-42637CRITICALCVSS 9.8EG 9.82024-08-16
H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- CVE-2024-41616CRITICALCVSS 9.8EG 9.82024-08-06
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
- CVE-2024-7332CRITICALCVSS 9.8EG 9.82024-08-01
A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of…
- CVE-2024-41611CRITICALCVSS 9.8EG 9.82024-07-30
In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.
- CVE-2024-41610CRITICALCVSS 9.8EG 9.82024-07-30
D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.
- CVE-2024-6912CRITICALCVSS 9.8EG 9.82024-07-22
Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.
- CVE-2024-35338CRITICALCVSS 9.8EG 9.82024-07-16
Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.
- CVE-2024-28747CRITICALCVSS 9.8EG 9.82024-07-09
An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.
- CVE-2023-46685CRITICALCVSS 9.8EG 9.82024-07-08
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.
- CVE-2024-4708CRITICALCVSS 9.8EG 9.82024-07-02
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
- CVE-2023-41919CRITICALCVSS 9.8EG 9.82024-07-02
Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.
- CVE-2024-39208CRITICALCVSS 9.8EG 9.82024-06-27
luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.
- CVE-2024-39374CRITICALCVSS 9.8EG 9.82024-06-27
TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.
- CVE-2024-0949CRITICALCVSS 9.8EG 9.82024-06-27
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.
- CVE-2024-36480CRITICALCVSS 9.8EG 9.82024-06-19
Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, uninte…
- CVE-2024-38466CRITICALCVSS 9.8EG 9.82024-06-16
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
- CVE-2024-38281CRITICALCVSS 9.8EG 9.82024-06-13
An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.
- CVE-2024-36264CRITICALCVSS 9.8EG 9.82024-06-12
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submari…
- CVE-2024-3700CRITICALCVSS 9.8EG 9.82024-06-10
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simpl…
- CVE-2024-3699CRITICALCVSS 9.8EG 9.82024-06-10
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet software versions…
- CVE-2024-1228CRITICALCVSS 9.8EG 9.82024-06-10
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia soft…
- CVE-2024-3408CRITICALCVSS 9.8EG 9.82024-06-06
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attacker…
- CVE-2024-36782CRITICALCVSS 9.8EG 9.82024-06-03
TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
- CVE-2024-5514CRITICALCVSS 9.8EG 9.82024-05-30
MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access contro…
- CVE-2024-35396CRITICALCVSS 9.8EG 9.82024-05-24
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.
- CVE-2024-32053CRITICALCVSS 9.8EG 9.82024-05-15
Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel b…
- CVE-2024-32740CRITICALCVSS 9.8EG 9.82024-05-14
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or over the network.
- CVE-2024-31810CRITICALCVSS 9.8EG 9.82024-05-14
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- CVE-2023-44411CRITICALCVSS 9.8EG 9.82024-05-03
D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not requi…
- CVE-2024-2161CRITICALCVSS 9.8EG 9.82024-03-21
Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .
- CVE-2024-24681CRITICALCVSS 9.8EG 9.82024-02-23
An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' install…
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →