CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,780 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 32 of 36
- CVE-2025-4633MEDIUMCVSS 6.5EG 6.52025-05-30
Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an unauthenticated malicious actor to log in via the web portal
- CVE-2025-46352CRITICALCVSS 9.8EG 9.82025-05-30
The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string in the binary responsible for running VNC. This password cannot be altered, allowing anyone with knowledge of it to ga…
- CVE-2025-46617HIGHCVSS 7.2EG 7.22025-04-25
Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. This affects StorNext RYO before 7.2.4, S…
- CVE-2025-47730MEDIUMCVSS 4.8EG 4.82025-05-08
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the passwor…
- CVE-2025-48413HIGHCVSS 7.7EG 7.72025-05-21
The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with the update files. There is no option for deleting or changing their passwords for an enduser…
- CVE-2025-48414MEDIUMCVSS 6.5EG 6.52025-05-21
There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functionality and are likely intended for debugging during developmen…
- CVE-2025-48491LOWCVSS 2.7EG 2.72025-05-30
Project AI is a platform designed to create AI agents. Prior to the pre-beta version, a hardcoded API key was present in the source code. This issue has been patched in the pre-beta version.
- CVE-2025-48748CRITICALCVSS 10.0EG 10.02025-05-29
Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
- CVE-2025-4876MEDIUMCVSS 6.0EG 6.02025-05-19
ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic …
- CVE-2025-49551HIGHCVSS 8.8EG 8.82025-07-08
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to …
- CVE-2025-5023HIGHCVSS 7.1EG 7.12025-07-10
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication range between…
- CVE-2025-51536CRITICALCVSS 9.8EG 9.82025-08-04
Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.
- CVE-2025-51606HIGHCVSS 8.8EG 8.82025-08-21
hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or compiled binary to forge valid access tokens and impersonate any user, including privileged …
- CVE-2025-5164HIGHCVSS 8.1EG 8.12025-05-26
A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack c…
- CVE-2025-52159HIGHCVSS 8.8EG 8.82025-09-19
Hardcoded credentials in default configuration of PPress 0.0.9.
- CVE-2025-52363MEDIUMCVSS 6.8EG 6.82025-07-14
Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image can extract and attempt to crack the root password hash, potentially obtainin…
- CVE-2025-52376CRITICALCVSS 9.8EG 9.82025-07-15
An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotely enable the Telnet service without authentication, bypassin…
- CVE-2025-52492HIGHCVSS 7.5EG 7.52025-07-07
A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz, contains hard-coded credentials for the Twilio API. A remote attacker who obtains a copy of the firmware can extract t…
- CVE-2025-53754MEDIUMCVSS 5.1EG 5.12025-07-16
This vulnerability exists in Digisol DG-GR6821AC Router due to hard-coded Root Access Credentials in system configuration of the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware …
- CVE-2025-5379MEDIUMCVSS 4.3EG 4.32025-05-31
A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects unknown code of the component Console Application. The manipulation of the argument CMCCAdmin/useradmin/CUAdmin leads …
- CVE-2025-53842MEDIUMCVSS 4.5EG 4.52025-07-16
Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerability is exploited, an attacker may tamper with the settings of the device by obtaining the credentials…
- CVE-2025-54341MEDIUMCVSS 5.3EG 5.32025-11-24
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuration values.
- CVE-2025-54454CRITICALCVSS 9.1EG 9.12025-07-23
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.
- CVE-2025-54455CRITICALCVSS 9.1EG 9.12025-07-23
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.
- CVE-2025-54465MEDIUMCVSS 6.8EG 6.82025-08-13
This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and anal…
- CVE-2025-54872HIGHCVSS 8.7EG 8.72025-08-06
onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor image if the secrets were copied from an existing onion domain. A website could be compromise…
- CVE-2025-54947CRITICALCVSS 9.8EG 9.82025-12-12
In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically genera…
- CVE-2025-55047HIGHCVSS 8.4EG 8.42025-09-09
CWE-798 Use of Hard-coded Credentials
- CVE-2025-55262HIGHCVSS 7.5EG 8.32026-03-26
HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the database.
- CVE-2025-55263HIGHCVSS 7.5EG 7.52026-03-26
HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure repositories, they can easily retrieve these hardcoded secrets.
- CVE-2025-55279MEDIUMCVSS 6.9EG 6.92025-08-13
This vulnerability exists in ZKTeco WL20 due to hard-coded private key stored in plaintext within the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and analyzing the binary da…
- CVE-2025-55739MEDIUMCVSS 5.1EG 5.12025-09-05
api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 16.0.14, 17.0.1 and 17.0.2, there is an identical OAuth private key used across multiple s…
- CVE-2025-56157CRITICALCVSS 9.8EG 9.82025-12-18
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port …
- CVE-2025-56466HIGHCVSS 7.5EG 7.52025-09-10
Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information.
- CVE-2025-56749CRITICALCVSS 9.4EG 9.42025-10-15
Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any us…
- CVE-2025-57434HIGHCVSS 8.8EG 8.82025-09-22
Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when the username is creabox and the password begins with the string creacast, regardless of what…
- CVE-2025-5751MEDIUMCVSS 6.8EG 6.82025-06-06
WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of WOLFBOX Level 2 EV Charger.…
- CVE-2025-57577HIGHCVSS 8.0EG 8.02025-09-12
An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "product lines enforce or clearly prompt users to change any initial credentials u…
- CVE-2025-57578HIGHCVSS 8.0EG 8.02025-09-12
An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password
- CVE-2025-57579HIGHCVSS 8.0EG 8.02025-09-12
An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password
- CVE-2025-57601CRITICALCVSS 9.8EG 9.82025-09-22
AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access to all managed IoT/edge devices. When an administrator initiates "Open Remote Terminal" from the AiKaan dashboard, the …
- CVE-2025-57602CRITICALCVSS 9.8EG 9.82025-09-22
Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH private key, allows remote attackers to authenticate to the cloud controller, gain interactive shell ac…
- CVE-2025-58269MEDIUMCVSS 5.3EG 5.32025-09-22
Use of Hard-coded Credentials vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 2.6.25.
- CVE-2025-58385HIGHCVSS 7.1EG 7.12025-09-26
In DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (there is hard-coded and predictable data).
- CVE-2025-58656MEDIUMCVSS 5.3EG 5.32025-09-22
Use of Hard-coded Credentials vulnerability in Risto Niinemets Estonian Shipping Methods for WooCommerce estonian-shipping-methods-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Estonian Shipping Methods for Woo…
- CVE-2025-58659MEDIUMCVSS 5.3EG 5.32025-09-22
Use of Hard-coded Credentials vulnerability in Essekia Helpie FAQ helpie-faq allows Retrieve Embedded Sensitive Data.This issue affects Helpie FAQ: from n/a through <= 1.45.
- CVE-2025-58744HIGHCVSS 7.5EG 7.52026-01-20
Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows decryption of document archive files using credentials decrypted with hard-coded application en…
- CVE-2025-59091CRITICALCVSS 9.3EG 9.32026-01-26
Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This in…
- CVE-2025-59092HIGHCVSS 8.7EG 8.72026-01-26
An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. This service is used for interprocess communication between services and the Kaba exos 9300 GUI, containing status inform…
- CVE-2025-59095MEDIUMCVSS 6.8EG 6.82026-01-26
The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is the function "EncryptAndDecrypt" in the library Kaba.EXOS.common.dll. This algorithm uses a simple XOR encryption techni…
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →