CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,779 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 23 of 36
- CVE-2023-28897MEDIUMCVSS 4.0EG 4.02024-01-12
The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulnerability discovered on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.
- CVE-2023-28937HIGHCVSS 8.8EG 8.82023-06-01
DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration software. ScriptRunner and ScriptRunner for Amazon SQS are used to start the configured processes on DataSpider Servis…
- CVE-2023-29064MEDIUMCVSS 4.1EG 4.12023-11-28
The FACSChorus software contains sensitive information stored in plaintext. A threat actor could gain hardcoded secrets used by the application, which include tokens and passwords for administrative accounts.
- CVE-2023-30351HIGHCVSS 7.5EG 7.52023-05-10
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UA…
- CVE-2023-30352CRITICALCVSS 9.8EG 9.82023-05-10
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.
- CVE-2023-30354CRITICALCVSS 9.8EG 9.82023-05-10
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.
- CVE-2023-30801CRITICALCVSS 9.8EG 9.82023-10-10
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote at…
- CVE-2023-30904MEDIUMCVSS 5.5EG 5.52023-06-16
A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information.
- CVE-2023-31173HIGHCVSS 7.7EG 7.72023-08-31
Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Windows allows Authentication Bypass. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details.…
- CVE-2023-31184MEDIUMCVSS 6.2EG 6.22023-05-30
ROZCOM client CWE-798: Use of Hard-coded Credentials
- CVE-2023-31240HIGHCVSS 8.3EG 8.32023-05-22
Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely. OvrC cloud contains a hidden superuser account accessible through hard-coded credentials.
- CVE-2023-31579CRITICALCVSS 9.8EG 9.82023-11-02
Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.
- CVE-2023-31581CRITICALCVSS 9.8EG 9.82023-10-25
Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.
- CVE-2023-31808HIGHCVSS 7.2EG 7.22023-09-19
Technicolor TG670 10.5.N.9 devices contain multiple accounts with hard-coded passwords. One account has administrative privileges, allowing for unrestricted access over the WAN interface if Remote Administration is enabled.
- CVE-2023-32077HIGHCVSS 7.5EG 7.52023-08-24
Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints. The issue is patched in 0.17.1 and fixed in 0.18.6. …
- CVE-2023-32145HIGHCVSS 8.8EG 8.82024-05-03
D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1360 routers. Authentication is not required t…
- CVE-2023-32227CRITICALCVSS 9.8EG 9.82023-07-30
Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials
- CVE-2023-32274HIGHCVSS 8.6EG 8.62023-06-20
Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.
- CVE-2023-3237MEDIUMCVSS 6.3EG 6.32023-06-14
A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input admin leads to use of hard-coded password. The exploit has bee…
- CVE-2023-32619HIGHCVSS 8.8EG 8.82023-09-06
Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use hard-coded credentials to login to the affected device, which may allow a network-adjacent unauthenti…
- CVE-2023-3262MEDIUMCVSS 6.7EG 6.72023-08-14
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database.A malicious agent with the ability to execute operating system commands on the d…
- CVE-2023-3264HIGHCVSS 6.7EG 8.42023-08-14
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating system commands on the…
- CVE-2023-33236CRITICALCVSS 9.8EG 9.82023-05-22
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.
- CVE-2023-33304MEDIUMCVSS 4.4EG 4.42023-11-14
A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials.
- CVE-2023-33371CRITICALCVSS 9.8EG 9.82023-08-03
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.
- CVE-2023-33372CRITICALCVSS 9.8EG 9.82023-08-04
Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker a…
- CVE-2023-33413HIGHCVSS 8.8EG 8.82023-12-07
The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote aut…
- CVE-2023-33744CRITICALCVSS 9.8EG 9.82023-07-27
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.
- CVE-2023-33778CRITICALCVSS 9.8EG 9.82023-06-01
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys whi…
- CVE-2023-33836MEDIUMCVSS 5.3EG 5.32023-10-16
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. …
- CVE-2023-33920MEDIUMCVSS 6.8EG 6.82023-06-13
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain the hash of the root password in a hard-coded form, which could be ex…
- CVE-2023-34123HIGHCVSS 7.5EG 7.52023-07-13
Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
- CVE-2023-34284MEDIUMCVSS 6.3EG 6.32024-05-03
NETGEAR RAX30 Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR RAX30 routers. Authentication is not requir…
- CVE-2023-34338HIGHCVSS 7.1EG 7.12023-07-05
AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and ava…
- CVE-2023-34473MEDIUMCVSS 6.6EG 6.62023-07-05
AMI SPx contains a vulnerability in the BMC where a valid user may cause a use of hard-coded credentials. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.
- CVE-2023-35724HIGHCVSS 8.8EG 8.82024-05-03
D-Link DAP-2622 Telnet CLI Use of Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2622 routers. Authentication…
- CVE-2023-35763MEDIUMCVSS 5.5EG 5.52023-07-18
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a cryptographic vulnerability that could allow an unauthenticated user to decrypt encrypted passwords into plaintext.
- CVE-2023-35987CRITICALCVSS 9.8EG 9.82023-07-06
PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
- CVE-2023-36013MEDIUMCVSS 6.5EG 6.52023-11-20
PowerShell Information Disclosure Vulnerability
- CVE-2023-36380CRITICALCVSS 9.8EG 9.82023-10-10
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)). The affected devices…
- CVE-2023-36623HIGHCVSS 7.8EG 7.82023-07-05
The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC address. This allows a local user to calculate the root password and escalate privileges.
- CVE-2023-36647HIGHCVSS 7.5EG 7.52023-12-12
A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.
- CVE-2023-36651HIGHCVSS 7.2EG 7.22023-12-12
Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consume the most privileged REST API endpoints via these credentials.
- CVE-2023-36817HIGHCVSS 7.5EG 7.52023-07-03
`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintentionally committed an…
- CVE-2023-37215MEDIUMCVSS 6.2EG 6.22023-07-30
JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials
- CVE-2023-37286CRITICALCVSS 9.8EG 9.82023-07-10
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.
- CVE-2023-37287CRITICALCVSS 9.1EG 9.12023-07-10
SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execute submission and ap…
- CVE-2023-37291HIGHCVSS 8.6EG 8.62023-07-21
Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access…
- CVE-2023-37426HIGHCVSS 7.4EG 7.42023-08-22
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature …
- CVE-2023-37608HIGHCVSS 7.5EG 7.52024-01-03
An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin account with astech as its hardcoded password.
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →