CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,778 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 20 of 36
- CVE-2022-34005CRITICALCVSS 9.8EG 9.82022-06-19
An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP Next…
- CVE-2022-34045CRITICALCVSS 9.8EG 9.82022-07-20
Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh.
- CVE-2022-34151HIGHCVSS 8.1EG 8.12022-07-04
Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series al…
- CVE-2022-34386MEDIUMCVSS 5.5EG 5.52023-02-11
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and …
- CVE-2022-34425HIGHCVSS 7.5EG 7.52022-10-10
Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.
- CVE-2022-34440CRITICALCVSS 8.4EG 9.82023-01-11
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerabilit…
- CVE-2022-34441CRITICALCVSS 8.0EG 9.82023-01-11
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerabili…
- CVE-2022-34442CRITICALCVSS 8.0EG 9.82023-01-18
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerabi…
- CVE-2022-34449MEDIUMCVSS 6.0EG 6.02023-02-11
PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the applicatio…
- CVE-2022-34462HIGHCVSS 8.4EG 8.42023-01-18
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to…
- CVE-2022-34840MEDIUMCVSS 6.5EG 6.52022-12-07
Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device. The affected products/versions are as follows: WZR-300HP firmware Ver. 2.00 a…
- CVE-2022-34906HIGHCVSS 7.5EG 7.52022-07-25
A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.
- CVE-2022-34907CRITICALCVSS 9.8EG 9.82022-07-25
An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over…
- CVE-2022-34993CRITICALCVSS 9.8EG 9.82022-08-04
Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.
- CVE-2022-35287HIGHCVSS 7.5EG 7.52022-07-25
IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of intern…
- CVE-2022-35413CRITICALCVSS 9.8EG 9.82022-09-13
WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.
- CVE-2022-35491CRITICALCVSS 9.8EG 9.82022-08-10
TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.
- CVE-2022-35540CRITICALCVSS 9.8EG 9.82022-08-18
Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.
- CVE-2022-35582HIGHCVSS 8.8EG 8.82022-09-13
Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has a built-in non-privileged user penta with a predefined password. The password for this us…
- CVE-2022-35734HIGHCVSS 7.5EG 7.52022-08-16
'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data …
- CVE-2022-35857CRITICALCVSS 9.8EG 9.82022-07-13
kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroConfig file.
- CVE-2022-35866CRITICALCVSS 9.8EG 9.82022-08-03
This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw exists within the con…
- CVE-2022-36159HIGHCVSS 8.8EG 8.82022-09-26
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malici…
- CVE-2022-36170HIGHCVSS 8.8EG 8.82022-08-19
MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitrary file deletion.
- CVE-2022-36171HIGHCVSS 8.1EG 8.12022-08-19
MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion.
- CVE-2022-36222HIGHCVSS 8.4EG 8.42022-12-21
Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used locally to access the web admin interface.
- CVE-2022-36558CRITICALCVSS 9.8EG 9.82022-08-29
Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.
- CVE-2022-36560CRITICALCVSS 9.8EG 9.82022-08-29
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh.
- CVE-2022-36610HIGHCVSS 7.8EG 7.82022-08-29
TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- CVE-2022-36611HIGHCVSS 7.8EG 7.82022-08-29
TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- CVE-2022-36612HIGHCVSS 7.8EG 7.82022-08-29
TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- CVE-2022-36613HIGHCVSS 7.8EG 7.82022-08-29
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- CVE-2022-36614HIGHCVSS 7.8EG 7.82022-08-29
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- CVE-2022-36615HIGHCVSS 7.8EG 7.82022-08-29
TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- CVE-2022-36616HIGHCVSS 7.8EG 7.82022-08-29
TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- CVE-2022-36672CRITICALCVSS 9.8EG 9.82022-09-01
Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.
- CVE-2022-36925HIGHCVSS 4.4EG 7.82023-01-09
Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used for IPC between the Zoom Rooms daemon service and the Zoom Rooms client was generated using parameters that could be o…
- CVE-2022-36952CRITICALCVSS 8.4EG 9.82022-07-27
In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
- CVE-2022-37255HIGHCVSS 7.5EG 7.52023-04-16
TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603.
- CVE-2022-3744MEDIUMCVSS 6.7EG 6.72023-08-23
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.
- CVE-2022-37710HIGHCVSS 7.8EG 7.82022-11-07
Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable fi…
- CVE-2022-37832CRITICALCVSS 9.8EG 9.82022-12-16
Mutiny 7.2.0-10788 suffers from Hardcoded root password.
- CVE-2022-37841HIGHCVSS 7.5EG 7.52022-09-06
In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.
- CVE-2022-37857HIGHCVSS 7.5EG 7.52022-09-08
bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.
- CVE-2022-38069MEDIUMCVSS 4.3EG 6.12022-09-13
Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of …
- CVE-2022-38116CRITICALCVSS 9.8EG 9.82022-08-30
Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote attacker can access, modify system data or disrupt service.
- CVE-2022-38117MEDIUMCVSS 5.5EG 5.52022-10-24
Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt users’ ciphertext and tamper with it.
- CVE-2022-38337CRITICALCVSS 9.1EG 9.12022-12-06
When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of Service (DoS) for the user if services like fail2ban are u…
- CVE-2022-38394CRITICALCVSS 9.8EG 9.82022-09-08
Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attacker to execute an arbitrary OS command.
- CVE-2022-38420HIGHCVSS 7.5EG 7.92022-10-14
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary service…
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →