CWE-798— Use of Hard-coded Credentials
1,582 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 15 of 32
- CVE-2021-41320MEDIUMCVSS 5.5EG 5.52021-10-15
A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than the average authenticated user. NOTE: the vendor disputes this because the password is not hardcoded (it can be changed d…
- CVE-2021-41827HIGHCVSS 7.5EG 7.52021-09-30
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive.
- CVE-2021-41828HIGHCVSS 7.5EG 7.52021-09-30
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.
- CVE-2021-41848HIGHCVSS 7.8EG 7.82022-03-11
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-party apps can provide a spoofed software update file that contains an arbitrary shell script and arbitrary ARM binary,…
- CVE-2021-4228MEDIUMCVSS 5.8EG 8.12022-10-24
Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the presence of the HTTPS connection. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.00.0.
- CVE-2021-42635HIGHCVSS 8.1EG 8.12022-01-31
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.
- CVE-2021-42833CRITICALCVSS 9.3EG 9.32022-02-07
A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.
- CVE-2021-42849MEDIUMCVSS 6.8EG 6.82022-05-18
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.
- CVE-2021-42850HIGHCVSS 8.8EG 7.82022-05-18
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.
- CVE-2021-42892MEDIUMCVSS 4.3EG 4.32022-06-03
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and password exists in the firmware.
- CVE-2021-43044CRITICALCVSS 9.8EG 9.82021-12-06
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.
- CVE-2021-43052CRITICALCVSS 9.3EG 9.32022-01-11
The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a ha…
- CVE-2021-43116HIGHCVSS 8.8EG 8.82022-07-05
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.
- CVE-2021-43136CRITICALCVSS 9.8EG 9.82021-11-10
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
- CVE-2021-43282MEDIUMCVSS 6.5EG 6.52021-11-30
An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device default Wi-Fi password corresponds to the last 4 bytes of t…
- CVE-2021-43284HIGHCVSS 7.8EG 7.82021-11-30
An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin …
- CVE-2021-43575MEDIUMCVSS 5.5EG 5.52021-11-09
KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information, a similar issue to CVE-2021-36799. NOTE: The vendor disputes this because it is not the…
- CVE-2021-44207HIGHCVSS 8.1EG 9.0⚠ KEV2021-12-21
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
- CVE-2021-44464MEDIUMCVSS 6.3EG 6.32022-01-21
Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across all instances. An attacker in possession of the password may gain privileges on all installations of this software.
- CVE-2021-44720HIGHCVSS 7.2EG 7.22022-08-12
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative …
- CVE-2021-45033HIGHCVSS 8.8EG 8.82022-01-11
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODU…
- CVE-2021-45106MEDIUMCVSS 6.5EG 6.52022-02-09
A vulnerability has been identified in SICAM TOOLBOX II (All versions). Affected applications use a circumventable access control within a database service. This could allow an attacker to access the database.
- CVE-2021-45458HIGHCVSS 7.5EG 7.52022-01-06
Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and IV. If users use cl…
- CVE-2021-45520CRITICALCVSS 9.6EG 9.62021-12-26
Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.
- CVE-2021-45521HIGHCVSS 7.4EG 7.42021-12-26
Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.
- CVE-2021-45522MEDIUMCVSS 6.1EG 6.12021-12-26
NETGEAR XR1000 devices before 1.0.0.58 are affected by a hardcoded password.
- CVE-2021-45732HIGHCVSS 8.8EG 8.82021-12-30
Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted/obfuscated. By extracti…
- CVE-2021-45841HIGHCVSS 8.1EG 8.12022-04-25
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused using a null/empty has…
- CVE-2021-45877CRITICALCVSS 9.8EG 9.82022-03-21
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port …
- CVE-2021-45913HIGHCVSS 7.2EG 7.22022-01-04
A hardcoded key in ControlUp Real-Time Agent (cuAgent.exe) before 8.2.5 may allow a potential attacker to run OS commands via a WCF channel.
- CVE-2021-46008HIGHCVSS 8.8EG 8.82022-03-30
In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turne…
- CVE-2021-46247HIGHCVSS 7.5EG 7.52022-02-17
The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00.
- CVE-2021-47730HIGHCVSS 8.8EG 8.82025-12-09
Selea Targa IP OCR-ANPR Camera contains a cross-site request forgery vulnerability that allows attackers to create administrative users without authentication. Attackers can craft a malicious web page that submits a form to add a new admin…
- CVE-2021-47744HIGHCVSS 7.5EG 7.52025-12-31
Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes root access. Attackers can exploit the static 'Chameleon' password to gain remote root access via Telnet or SSH on aff…
- CVE-2021-47796CRITICALCVSS 9.8EG 9.82026-01-16
Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attackers to access a Linux shell. Attackers can connect to port 23 using the default credential to execute arbitrary command…
- CVE-2022-0131LOWCVSS 3.3EG 3.32022-01-17
Jimoty App for Android versions prior to 3.7.42 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.
- CVE-2022-1162CRITICALCVSS 9.1EG 9.82022-04-04
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take o…
- CVE-2022-1400HIGHCVSS 7.1EG 9.82022-08-17
Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device4…
- CVE-2022-1701HIGHCVSS 7.5EG 7.52022-05-13
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.
- CVE-2022-20773HIGHCVSS 7.5EG 8.12022-04-21
A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host key.…
- CVE-2022-20844MEDIUMCVSS 5.3EG 5.32022-09-30
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC using a default static use…
- CVE-2022-20868MEDIUMCVSS 4.7EG 8.82022-11-04
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected s…
- CVE-2022-2107CRITICALCVSS 9.8EG 9.82022-07-20
The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the G…
- CVE-2022-21194CRITICALCVSS 9.8EG 9.82022-03-11
The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from …
- CVE-2022-21199MEDIUMCVSS 5.9EG 5.92022-01-28
An information disclosure vulnerability exists due to the hardcoded TLS key of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker can perform a …
- CVE-2022-21669CRITICALCVSS 9.1EG 9.12022-01-11
PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicly exposed in main.py, making it accessible to malicious actors. The bot token has been revoked and new version is already running on the serv…
- CVE-2022-22056CRITICALCVSS 9.8EG 9.82022-01-14
The Le-yan dental management system contains a hard-coded credentials vulnerability in the web page source code, which allows an unauthenticated remote attacker to acquire administrator’s privilege and control the system or disrupt servi…
- CVE-2022-22144CRITICALCVSS 9.8EG 9.82022-08-05
A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a known root passwor…
- CVE-2022-22466MEDIUMCVSS 6.8EG 6.82023-10-23
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. …
- CVE-2022-22512CRITICALCVSS 9.8EG 9.12023-03-23
Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →