CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,780 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 30 of 36
- CVE-2025-13252HIGHCVSS 7.3EG 7.32025-11-16
A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Affected by this issue is some unknown functionality of the component RSA/OAuth2/Database. The manipulation results in hard-code…
- CVE-2025-13776HIGHCVSS 7.1EG 7.12026-02-24
Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content. This vulne…
- CVE-2025-1393CRITICALCVSS 9.8EG 9.82025-03-05
An unauthenticated remote attacker can use hard-coded credentials to gain full administration privileges on the affected product.
- CVE-2025-13954CRITICALCVSS 9.3EG 9.32025-12-10
Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authorization checks and gain full access to the admin UI
- CVE-2025-13957HIGHCVSS 7.5EG 7.52026-03-10
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS P…
- CVE-2025-14096HIGHCVSS 8.4EG 8.42025-12-17
A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possibility to extract credential information. The vulnerability is due to a weakness in the design and insufficient credent…
- CVE-2025-14115HIGHCVSS 8.4EG 8.42026-01-20
IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBM® Sterling Connect:Direct for UNIX contains hard-coded credentials, such as a password or cryptographic…
- CVE-2025-14126HIGHCVSS 8.8EG 8.82025-12-06
A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the component Web Interface. Such manipulation leads to hard-coded credentials. The attack needs to be initiated within the …
- CVE-2025-14611CRITICALCVSS 9.8EG 9.8⚠ KEV2025-12-12
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary…
- CVE-2025-14923CRITICALCVSS 9.8EG 9.82026-03-03
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
- CVE-2025-15105LOWCVSS 3.7EG 3.72025-12-27
A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxun/maxun/blob/develop/server/src/routes/auth.ts. Performing manipulation of the argument api_key results in use of hard-…
- CVE-2025-15107LOWCVSS 3.7EG 3.72025-12-27
A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown function of the file sqle/utils/jwt.go of the component JWT Secret Handler. The manipulation of the argument JWTSecretKey lead…
- CVE-2025-15111CRITICALCVSS 9.8EG 9.82025-12-30
Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain fu…
- CVE-2025-15371HIGHCVSS 7.8EG 7.82025-12-31
A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. Affected is an unknown function of the component Shadow File. Such manipulation with the input Fireitup leads to hard-co…
- CVE-2025-15605HIGHCVSS 7.3EG 7.32026-03-23
A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, …
- CVE-2025-1724HIGHCVSS 7.4EG 7.42025-03-17
Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.
- CVE-2025-1879LOWCVSS 2.4EG 2.42025-03-03
A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some unknown processing of the component APK. The manipulation leads to hard-coded credentials. It is possible to launch the …
- CVE-2025-20188CRITICALCVSS 10.0EG 10.02025-05-07
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remot…
- CVE-2025-20309CRITICALCVSS 10.0EG 10.02025-07-02
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using…
- CVE-2025-23179MEDIUMCVSS 5.5EG 5.52025-04-29
CWE-798: Use of Hard-coded Credentials
- CVE-2025-2322HIGHCVSS 7.3EG 7.32025-03-15
A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been classified as critical. This affects an unknown part of the file /chatgpt-boot/src/main/java/org/springblade/modules/mjkj/controller/OpenController.java.…
- CVE-2025-2342MEDIUMCVSS 5.3EG 5.32025-03-16
A vulnerability classified as critical has been found in IROAD X5 Mobile App up to 5.2.5 on Android. Affected is an unknown function of the component API Endpoint. The manipulation leads to hard-coded credentials. It is possible to launch …
- CVE-2025-2343HIGHCVSS 7.5EG 7.52025-03-16
A vulnerability classified as critical was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this vulnerability is an unknown functionality of the component Device Pairing. The manipulation leads to hard-coded credenti…
- CVE-2025-2394MEDIUMCVSS 4.7EG 4.72025-05-23
Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure.
- CVE-2025-2538CRITICALCVSS 9.8EG 9.82025-03-20
A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated attacker to gain administrative access to the system.
- CVE-2025-2556MEDIUMCVSS 4.3EG 4.32025-03-20
A vulnerability classified as problematic was found in Audi UTR Dashcam 2.0. Affected by this vulnerability is an unknown functionality of the component Video Stream Handler. The manipulation leads to hard-coded credentials. The attack can…
- CVE-2025-25570CRITICALCVSS 9.8EG 9.82025-02-27
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.
- CVE-2025-26398MEDIUMCVSS 5.6EG 5.62025-08-12
SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional softwa…
- CVE-2025-26410CRITICALCVSS 9.8EG 9.82025-02-11
The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via …
- CVE-2025-26476HIGHCVSS 8.4EG 8.42025-08-04
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthoriz…
- CVE-2025-27255HIGHCVSS 8.0EG 8.02025-03-10
Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code.
- CVE-2025-27488MEDIUMCVSS 6.7EG 6.72025-05-13
Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.
- CVE-2025-27643CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Hardcoded AWS API Key V-2024-006.
- CVE-2025-2765HIGHCVSS 8.8EG 8.82025-04-23
CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of CarlinKit CPC200-CCPA devices. Au…
- CVE-2025-28230CRITICALCVSS 9.1EG 9.12025-04-18
Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.
- CVE-2025-28388CRITICALCVSS 9.8EG 9.82025-06-13
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
- CVE-2025-29268CRITICALCVSS 9.8EG 9.82025-12-04
ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.
- CVE-2025-30109MEDIUMCVSS 6.5EG 6.52025-03-18
In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded credentials that allow an attacker on the local Wi-Fi network to access API endpoints and…
- CVE-2025-30113CRITICALCVSS 9.8EG 9.82025-03-18
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashcam's Android application contains hardcoded credentials that allow unauthorized access to d…
- CVE-2025-30118HIGHCVSS 7.5EG 7.52025-03-25
An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses the same default credentials for all devices and does not implement proper multi-device authentication, allowing attac…
- CVE-2025-30122CRITICALCVSS 9.8EG 9.82025-03-18
An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for attackers to gain unauthorized access to multiple devices.
- CVE-2025-30123CRITICALCVSS 9.8EG 9.82025-03-18
An issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the FTPX user account, enabling attackers to gain unauthorized access and extract sensitive recorded footage from the device.
- CVE-2025-30125CRITICALCVSS 9.8EG 9.82025-07-28
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an insecure-by-default condition. For users who change their passwords, it's limited …
- CVE-2025-30137CRITICALCVSS 9.8EG 9.82025-03-18
An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for ports 9091 and 9092. The GNET mobile application contains hardcoded credentials that provide unauthorized access to the dashcam's API endpoints …
- CVE-2025-30198MEDIUMCVSS 6.3EG 6.32025-09-05
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.
- CVE-2025-30200MEDIUMCVSS 6.3EG 6.32025-09-05
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.
- CVE-2025-30406CRITICALCVSS 9.0EG 9.0⚠ KEV2025-04-03
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who…
- CVE-2025-31953HIGHCVSS 7.1EG 7.12025-07-24
HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.
- CVE-2025-32888HIGHCVSS 7.3EG 7.32025-05-01
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goTenna server is hardcoded in the app.
- CVE-2025-32889HIGHCVSS 7.3EG 7.32025-05-01
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sending SMS through a goTenna server is hardcoded in the app.
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →