CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,780 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 25 of 36
- CVE-2023-46685CRITICALCVSS 9.8EG 9.82024-07-08
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.
- CVE-2023-46706CRITICALCVSS 9.1EG 9.12024-02-01
Multiple MachineSense devices have credentials unable to be changed by the user or administrator.
- CVE-2023-46711MEDIUMCVSS 4.6EG 4.62023-12-26
VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the password of a specific product user.
- CVE-2023-46918MEDIUMCVSS 4.6EG 4.62023-12-27
Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access …
- CVE-2023-46919MEDIUMCVSS 6.3EG 6.32023-12-27
Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K (AES) encryption key. An attacker with physical access to the appl…
- CVE-2023-46943CRITICALCVSS 9.1EG 9.12024-01-13
An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC secret poses a risk because attackers can use the predictable secret to…
- CVE-2023-47213CRITICALCVSS 9.8EG 9.82023-11-16
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EAB…
- CVE-2023-47315HIGHCVSS 8.8EG 8.82023-11-22
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is hardcoded into the source code available to anyone on Git Hub. This secret is used to sign the application’s JWT token …
- CVE-2023-47704HIGHCVSS 7.5EG 7.52023-12-20
IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220.
- CVE-2023-47800CRITICALCVSS 9.8EG 9.82023-11-10
Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions su…
- CVE-2023-48053HIGHCVSS 7.5EG 7.52023-11-16
Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
- CVE-2023-48055HIGHCVSS 7.5EG 7.52023-11-16
SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the disclosure of information and communications.
- CVE-2023-48250HIGHCVSS 8.1EG 8.12024-01-10
The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.
- CVE-2023-48251HIGHCVSS 8.1EG 8.12024-01-10
The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.
- CVE-2023-48374MEDIUMCVSS 6.5EG 6.52023-12-15
SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific account with low privilege. An unauthenticated remote attacker can exploit this vulnerability to run partial processes a…
- CVE-2023-48388CRITICALCVSS 9.8EG 9.82023-12-15
Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.
- CVE-2023-48392CRITICALCVSS 9.8EG 9.82023-12-15
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with a…
- CVE-2023-49221HIGHCVSS 7.8EG 7.82024-06-07
Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and access the service menu, because there is a hard-coded service code.
- CVE-2023-49222HIGHCVSS 8.8EG 8.82024-06-07
Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root privileges.
- CVE-2023-49223HIGHCVSS 8.8EG 8.82024-06-07
Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An attacker could exploit this to extract files and obtain sensitive information.
- CVE-2023-49224HIGHCVSS 8.0EG 8.82024-06-07
Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use this key to gain root privileges.
- CVE-2023-49228MEDIUMCVSS 6.4EG 6.42023-12-28
An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root.
- CVE-2023-49253CRITICALCVSS 9.8EG 9.82024-01-12
Root user password is hardcoded into the device and cannot be changed in the user interface.
- CVE-2023-49256HIGHCVSS 7.5EG 7.52024-01-12
It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.
- CVE-2023-50124MEDIUMCVSS 6.8EG 6.82024-01-11
Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain design choices, an attacker can unlock the Flient Smart Door Lock by replacing the finger…
- CVE-2023-5074CRITICALCVSS 9.8EG 9.82023-09-20
Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28
- CVE-2023-50948CRITICALCVSS 9.8EG 9.82024-01-08
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal…
- CVE-2023-50974MEDIUMCVSS 5.5EG 5.52024-01-09
In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.
- CVE-2023-51588HIGHCVSS 7.8EG 7.82024-05-03
Voltronic Power ViewPower Pro MySQL Use of Hard-coded Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Voltronic Power ViewPower Pro. An att…
- CVE-2023-51629HIGHCVSS 8.8EG 8.82024-05-03
D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DCS-8300LHV2 IP cameras. Authentication is not r…
- CVE-2023-51638CRITICALCVSS 9.8EG 9.82024-11-22
Allegra Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. T…
- CVE-2023-51840CRITICALCVSS 9.8EG 9.82024-01-29
DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.
- CVE-2023-52723HIGHCVSS 7.1EG 7.12024-04-29
In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.
- CVE-2023-5318HIGHCVSS 7.5EG 7.52023-09-30
Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.
- CVE-2023-53983CRITICALCVSS 9.8EG 9.82025-12-30
Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex …
- CVE-2023-5456HIGHCVSS 8.1EG 8.12024-03-05
A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service and all included data with the same privileges of the web ap…
- CVE-2023-5777CRITICALCVSS 9.8EG 9.82023-11-06
Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote co…
- CVE-2023-6198CRITICALCVSS 9.3EG 9.32024-06-25
Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows unauthorized access to the device.
- CVE-2023-6255HIGHCVSS 7.5EG 7.52024-02-15
Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive Strings Within an Executable. This issue affects SoliPay Mobile App: before 5.0.8.
- CVE-2023-6409HIGHCVSS 7.7EG 7.72024-02-14
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert.
- CVE-2023-6448CRITICALCVSS 9.8EG 9.8⚠ KEV2023-12-05
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
- CVE-2023-6482MEDIUMCVSS 5.2EG 5.22024-01-27
Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This may allow an atta…
- CVE-2024-0390CRITICALCVSS 9.8EG 9.82024-02-15
INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access …
- CVE-2024-0865HIGHCVSS 7.8EG 7.82024-06-12
CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.
- CVE-2024-0949CRITICALCVSS 9.8EG 9.82024-06-27
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.
- CVE-2024-10025CRITICALCVSS 9.1EG 9.12024-10-17
A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if…
- CVE-2024-1039CRITICALCVSS 9.8EG 9.82024-02-01
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.
- CVE-2024-10451MEDIUMCVSS 5.9EG 5.92024-11-25
A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosure…
- CVE-2024-10748LOWCVSS 2.5EG 2.52024-11-04
A vulnerability, which was classified as problematic, has been found in Cosmote Greece What's Up App 4.47.3 on Android. This issue affects some unknown processing of the file gr/desquared/kmmsharedmodule/db/RealmDB.java of the component Re…
- CVE-2024-10920LOWCVSS 3.1EG 3.12024-11-06
A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\src\main\java\io\github\mariazevedo88\travel…
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →