CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,780 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 31 of 36
- CVE-2025-32985CRITICALCVSS 9.8EG 9.82025-04-25
NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.
- CVE-2025-33089MEDIUMCVSS 9.8EG 6.52026-02-17
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard coded user credentials.
- CVE-2025-33100MEDIUMCVSS 6.2EG 6.22025-08-18
IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal…
- CVE-2025-33186HIGHCVSS 8.8EG 8.82025-11-11
NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.
- CVE-2025-3321CRITICALCVSS 9.4EG 9.42025-06-06
A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the network, only by local users on the server.
- CVE-2025-33222CRITICALCVSS 9.8EG 9.82025-12-23
NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and data …
- CVE-2025-34034HIGHCVSS 8.8EG 8.82025-06-24
A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. Th…
- CVE-2025-34196CRITICALCVSS 9.8EG 9.82025-09-29
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments) contain a hardcoded private key for the PrinterLogic Certificate Authority (CA) and a ha…
- CVE-2025-34197HIGHCVSS 7.8EG 7.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951, Application prior to 20.0.2368 (VA and SaaS deployments) contain an undocumented local user account named ubuntu with a preset password and a sudoers e…
- CVE-2025-34198CRITICALCVSS 9.8EG 9.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951 and Application prior to 20.0.2368 (VA and SaaS deployments) contain shared, hardcoded SSH host private keys in the appliance image. The same private ho…
- CVE-2025-34209HIGHCVSS 7.2EG 7.22025-09-29
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.862 and Application prior to 20.0.2014 (VA and SaaS deployments) contain Docker images with the private GPG key and passphrase for the account *no‑reply+virtual��…
- CVE-2025-34223CRITICALCVSS 9.8EG 9.82025-09-29
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) contain a default admin account and an installation‑time endpoint at `/admin/quer…
- CVE-2025-3426HIGHCVSS 7.2EG 7.22025-04-07
We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disasse…
- CVE-2025-34501HIGHCVSS 7.0EG 7.02025-11-03
Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HTTP, Telnet, SMB, X11) are enabled by default. If an attacker can reach these interfaces - …
- CVE-2025-34509HIGHCVSS 7.5EG 8.52025-06-17
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticat…
- CVE-2025-35451CRITICALCVSS 9.8EG 9.82025-09-05
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be…
- CVE-2025-35452CRITICALCVSS 9.8EG 9.82025-09-05
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.
- CVE-2025-35940HIGHCVSS 8.1EG 8.12025-06-10
The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL endpoints.
- CVE-2025-36087HIGHCVSS 8.1EG 8.12025-10-13
IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which…
- CVE-2025-3621CRITICALCVSS 9.6EG 9.62025-07-15
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems. * vulnerabilities: * Improper Neutralization of Special Elements used in a Command ('Command Injec…
- CVE-2025-36572MEDIUMCVSS 6.5EG 6.52025-05-28
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially …
- CVE-2025-36747CRITICALCVSS 9.8EG 9.82025-12-13
ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to…
- CVE-2025-36752CRITICALCVSS 9.8EG 9.82025-12-13
Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that …
- CVE-2025-37103CRITICALCVSS 9.8EG 9.82025-07-08
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrativ…
- CVE-2025-37111MEDIUMCVSS 6.0EG 6.02025-07-31
A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive sys…
- CVE-2025-37112MEDIUMCVSS 6.0EG 6.02025-07-31
A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system …
- CVE-2025-3831HIGHCVSS 8.1EG 8.12025-08-12
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
- CVE-2025-38741HIGHCVSS 7.5EG 7.52025-08-04
Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.
- CVE-2025-4041CRITICALCVSS 9.3EG 9.32025-05-06
In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh server and utilize the system's components to perform OS command executions.
- CVE-2025-4049HIGHCVSS 8.6EG 8.62025-07-21
Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate local-stored database.This issue affects FARA: through 5.0.80.34.
- CVE-2025-40537HIGHCVSS 7.5EG 7.52026-01-28
SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions.
- CVE-2025-40938HIGHCVSS 8.1EG 8.12025-12-09
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the…
- CVE-2025-41109MEDIUMCVSS 4.6EG 4.62025-10-22
Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. The vulnerability is due to the lack of authentication mechanisms when establishing connections through these ports. Spe…
- CVE-2025-4130HIGHCVSS 7.5EG 7.52025-07-21
Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable. This issue affects PAVO Pay: before 13.05.2025.
- CVE-2025-41380MEDIUMCVSS 6.1EG 6.12025-05-23
Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a local user to retrieve the SSH hash string.
- CVE-2025-41696MEDIUMCVSS 4.6EG 4.62025-12-09
An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.
- CVE-2025-41710MEDIUMCVSS 6.5EG 6.52026-03-10
An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges.
- CVE-2025-41722HIGHCVSS 7.5EG 7.52025-10-22
The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attacker can extract private keys from the Software of the affected devices.
- CVE-2025-42890CRITICALCVSS 10.0EG 10.02025-11-11
SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentia…
- CVE-2025-4378CRITICALCVSS 10.0EG 10.02025-06-24
Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass. This issue affects ATA-AOF Mobile Applicatio…
- CVE-2025-43982CRITICALCVSS 9.8EG 9.82025-08-13
Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden hard-coded root account that cannot be disabled in the GUI.
- CVE-2025-44643HIGHCVSS 8.6EG 8.62025-08-04
Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R v1.4.9. The setting of the password property in the ripd.conf configuration file sets a hardcoded weak password, posin…
- CVE-2025-45466HIGHCVSS 8.8EG 8.82025-07-25
Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.
- CVE-2025-4569HIGHCVSS 7.7EG 7.72025-07-21
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. Refer to the 'Security Update for for MyASUS' section on the…
- CVE-2025-4570MEDIUMCVSS 6.9EG 6.92025-07-21
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. Refer to the 'Security Update for for MyASUS' section on the…
- CVE-2025-45746CRITICALCVSS 6.5EG 9.82025-05-13
In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is t…
- CVE-2025-45784CRITICALCVSS 9.8EG 9.82025-06-18
D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user credentials. An attacker with access to the firmware image can extract these credentials using s…
- CVE-2025-45813CRITICALCVSS 9.8EG 9.82025-07-02
ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.
- CVE-2025-46273CRITICALCVSS 9.8EG 9.82025-04-24
UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devices.
- CVE-2025-46274CRITICALCVSS 9.8EG 9.82025-04-24
UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed database.
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →