CWE-259— Use of Hard-coded Password
176 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-259page 2 of 4
- CVE-2023-32145HIGHCVSS 8.8EG 8.82024-05-03
D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1360 routers. Authentication is not required t…
- CVE-2023-3237MEDIUMCVSS 6.3EG 6.32023-06-14
A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input admin leads to use of hard-coded password. The exploit has bee…
- CVE-2023-37231CRITICALCVSS 9.8EG 9.82024-09-10
Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.
- CVE-2023-41030MEDIUMCVSS 6.3EG 6.32023-09-18
Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user.
- CVE-2023-41713HIGHCVSS 7.5EG 7.52023-10-17
SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.
- CVE-2023-46685CRITICALCVSS 9.8EG 9.82024-07-08
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.
- CVE-2023-49963HIGHCVSS 8.8EG 8.82024-04-19
DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control.
- CVE-2023-50948MEDIUMCVSS 6.5EG 6.52024-01-08
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal…
- CVE-2023-51629HIGHCVSS 8.8EG 6.32024-05-03
D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DCS-8300LHV2 IP cameras. Authentication is not r…
- CVE-2023-5222MEDIUMCVSS 6.3EG 9.02023-09-27
A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of the component Web Management Interface. The manipulation lea…
- CVE-2024-11026LOWCVSS 3.7EG 3.72024-11-08
A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ch/qos/logback/core/net/ssl/SSL.java of the component Keystore…
- CVE-2024-11630HIGHCVSS 7.3EG 7.32024-11-22
A vulnerability has been found in E-Lins H685, H685f, H700, H720, H750, H820, H820Q, H820Q0 and H900 up to 3.2 and classified as critical. This vulnerability affects unknown code of the component OEM Backend. The manipulation leads to hard…
- CVE-2024-1228CRITICALCVSS 9.8EG 9.82024-06-10
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia soft…
- CVE-2024-2038HIGHCVSS 7.5EG 7.52024-05-23
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.22.6. This is due to the use of hardcoded credentials to authentic…
- CVE-2024-20412CRITICALCVSS 9.3EG 9.32024-10-23
A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerabil…
- CVE-2024-2197MEDIUMCVSS 4.3EG 9.12024-03-20
The Chirp Access app contains a hard-coded password, BEACON_PASSWORD. An attacker within Bluetooth range could change configuration settings within the Bluetooth beacon, effectively disabling the application's ability to notify users when …
- CVE-2024-21990MEDIUMCVSS 5.4EG 5.42024-04-17
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentials.
- CVE-2024-2420CRITICALCVSS 9.8EG 9.82024-05-30
LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypass authentication requirements.
- CVE-2024-25825CRITICALCVSS 9.8EG 9.82024-10-09
FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.
- CVE-2024-26196MEDIUMCVSS 4.3EG 4.32024-03-21
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
- CVE-2024-27164HIGHCVSS 7.1EG 7.12024-06-14
Toshiba printers contain hardcoded credentials. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27488CRITICALCVSS 9.8EG 9.82024-04-08
Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the s…
- CVE-2024-27774HIGHCVSS 7.5EG 7.52024-03-18
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device's Firmware
- CVE-2024-28010CRITICALCVSS 9.8EG 9.82024-03-28
Use of Hard-coded Password in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2,…
- CVE-2024-28023MEDIUMCVSS 5.7EG 5.72024-06-11
A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary cod…
- CVE-2024-28066HIGHCVSS 8.8EG 8.82024-04-08
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
- CVE-2024-29011HIGHCVSS 7.5EG 7.52024-05-01
Use of hard-coded password in the GMS ECM endpoint leading to authentication bypass vulnerability. This issue affects GMS: 9.3.4 and earlier versions.
- CVE-2024-31798MEDIUMCVSS 6.8EG 6.42024-08-15
Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices
- CVE-2024-31810CRITICALCVSS 9.8EG 9.82024-05-14
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- CVE-2024-32210MEDIUMCVSS 5.3EG 5.32024-05-01
The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default for forms and SQL connections.
- CVE-2024-32741CRITICALCVSS 10.0EG 10.02024-05-14
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who …
- CVE-2024-33625CRITICALCVSS 9.8EG 9.82024-05-15
CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.
- CVE-2024-33867MEDIUMCVSS 4.8EG 4.82024-05-14
An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.
- CVE-2024-34025CRITICALCVSS 9.8EG 9.82024-05-15
CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges.
- CVE-2024-34211HIGHCVSS 8.8EG 8.82024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
- CVE-2024-34539CRITICALCVSS 9.4EG 9.42024-06-14
Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also be used to login to the administration panel and to perform privileged ac…
- CVE-2024-35395HIGHCVSS 8.8EG 8.82024-05-24
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
- CVE-2024-36526CRITICALCVSS 9.8EG 9.82024-07-09
ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.
- CVE-2024-3699CRITICALCVSS 9.8EG 9.82024-06-10
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet software versions…
- CVE-2024-3700CRITICALCVSS 9.8EG 9.82024-06-10
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simpl…
- CVE-2024-37644HIGHCVSS 8.8EG 8.82024-06-14
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
- CVE-2024-38885HIGHCVSS 7.5EG 7.52024-08-02
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known operating system credentials due to hardcoded SQL user cr…
- CVE-2024-38902CRITICALCVSS 9.8EG 9.82024-06-24
H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- CVE-2024-39345HIGHCVSS 7.2EG 7.22024-07-24
AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account whose password is based on the devices MAC address. All of the devices internet interfaces …
- CVE-2024-39585HIGHCVSS 7.9EG 7.92024-09-06
Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading …
- CVE-2024-41616CRITICALCVSS 9.8EG 8.82024-08-06
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
- CVE-2024-42639CRITICALCVSS 9.8EG 9.82024-08-16
H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root.
- CVE-2024-43423CRITICALCVSS 9.8EG 9.82024-09-25
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.
- CVE-2024-46328HIGHCVSS 8.0EG 8.02024-09-26
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts, including root.
- CVE-2024-46959MEDIUMCVSS 6.5EG 6.52024-09-18
runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows access to the /stream1 URI via the rtsp:// protocol to receive the video and audio stream.
Map vulnerabilities like CWE-259 to your infrastructure
EchelonGraph correlates every CVE — across CWE-259 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →