CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 6 of 39
- CVE-2024-0390CRITICALCVSS 9.8EG 9.82024-02-15
INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access …
- CVE-2024-23816CRITICALCVSS 9.8EG 9.82024-02-13
A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non…
- CVE-2023-38995CRITICALCVSS 9.8EG 9.82024-02-07
An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command.
- CVE-2024-22853CRITICALCVSS 9.8EG 9.82024-02-06
D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.
- CVE-2024-21764CRITICALCVSS 9.8EG 9.82024-02-02
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port.
- CVE-2024-1039CRITICALCVSS 9.8EG 9.82024-02-01
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.
- CVE-2024-24324CRITICALCVSS 9.8EG 9.82024-01-30
TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.
- CVE-2023-51840CRITICALCVSS 9.8EG 9.82024-01-29
DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.
- CVE-2024-23619CRITICALCVSS 9.8EG 9.82024-01-26
A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerability to achieve information disclosure or remote code execution.
- CVE-2023-49253CRITICALCVSS 9.8EG 9.82024-01-12
Root user password is hardcoded into the device and cannot be changed in the user interface.
- CVE-2023-50948CRITICALCVSS 9.8EG 9.82024-01-08
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal…
- CVE-2023-43870CRITICALCVSS 9.8EG 9.82023-12-19
When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or reverse engineer the source code to gain access to the root certificate password. Using t…
- CVE-2023-48392CRITICALCVSS 9.8EG 9.82023-12-15
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with a…
- CVE-2023-48388CRITICALCVSS 9.8EG 9.82023-12-15
Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.
- CVE-2023-40300CRITICALCVSS 9.8EG 9.82023-12-07
NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.
- CVE-2023-39169CRITICALCVSS 9.8EG 9.82023-12-07
The affected devices use publicly available default credentials with administrative privileges.
- CVE-2023-23324CRITICALCVSS 9.8EG 9.82023-11-29
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account.
- CVE-2023-47213CRITICALCVSS 9.8EG 9.82023-11-16
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EAB…
- CVE-2023-47800CRITICALCVSS 9.8EG 9.82023-11-10
Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions su…
- CVE-2023-41137CRITICALCVSS 9.8EG 9.82023-11-09
Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engineering the client and used to impersonate the AppsAnywhere server.
- CVE-2023-5777CRITICALCVSS 9.8EG 9.82023-11-06
Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote co…
- CVE-2023-31579CRITICALCVSS 9.8EG 9.82023-11-02
Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.
- CVE-2023-45499CRITICALCVSS 9.8EG 9.82023-10-27
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.
- CVE-2018-17558CRITICALCVSS 9.8EG 9.82023-10-26
Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 …
- CVE-2023-42492CRITICALCVSS 9.8EG 9.82023-10-25
EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key
- CVE-2023-31581CRITICALCVSS 9.8EG 9.82023-10-25
Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.
- CVE-2023-30801CRITICALCVSS 9.8EG 9.82023-10-10
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote at…
- CVE-2023-36380CRITICALCVSS 9.8EG 9.82023-10-10
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)). The affected devices…
- CVE-2023-20101CRITICALCVSS 9.8EG 9.82023-10-04
A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerabi…
- CVE-2023-41878CRITICALCVSS 9.8EG 9.82023-09-27
MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing and performance testing. The Selenium VNC config used in Metersphere is using a weak password by def…
- CVE-2023-5074CRITICALCVSS 9.8EG 9.82023-09-20
Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28
- CVE-2023-41030CRITICALCVSS 9.8EG 9.82023-09-18
Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user.
- CVE-2023-42336CRITICALCVSS 9.8EG 9.82023-09-16
An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component.
- CVE-2023-37755CRITICALCVSS 9.8EG 9.82023-09-14
i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers …
- CVE-2023-41508CRITICALCVSS 9.8EG 9.82023-09-05
A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.
- CVE-2023-38026CRITICALCVSS 9.8EG 9.82023-08-28
SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.
- CVE-2023-38024CRITICALCVSS 9.8EG 9.82023-08-28
SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system oper…
- CVE-2023-39808CRITICALCVSS 9.8EG 9.82023-08-21
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWv…
- CVE-2023-4204CRITICALCVSS 9.8EG 9.82023-08-16
NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses a potential risk to the security and integrity of the affected device. This vulnerability is attributed to the presenc…
- CVE-2023-33372CRITICALCVSS 9.8EG 9.82023-08-04
Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker a…
- CVE-2023-33371CRITICALCVSS 9.8EG 9.82023-08-03
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.
- CVE-2023-32227CRITICALCVSS 9.8EG 9.82023-07-30
Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials
- CVE-2023-33744CRITICALCVSS 9.8EG 9.82023-07-27
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.
- CVE-2023-37286CRITICALCVSS 9.8EG 9.82023-07-10
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.
- CVE-2023-35987CRITICALCVSS 9.8EG 9.82023-07-06
PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
- CVE-2023-2611CRITICALCVSS 9.8EG 9.82023-06-22
Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users.
- CVE-2022-4333CRITICALCVSS 9.8EG 9.82023-06-01
Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines.
- CVE-2023-33778CRITICALCVSS 9.8EG 9.82023-06-01
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys whi…
- CVE-2023-33236CRITICALCVSS 9.8EG 9.82023-05-22
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.
- CVE-2023-30354CRITICALCVSS 9.8EG 9.82023-05-10
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →