CWE-798— Use of Hard-coded Credentials
1,580 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 4 of 32
- CVE-2018-15781HIGHCVSS 7.9EG 8.02019-02-13
The Dell Wyse Password Encoder in ThinLinux2 versions prior to 2.1.0.01 contain a Hard-coded Cryptographic Key vulnerability. An unauthenticated remote attacker could reverse engineer the cryptographic system used in the Dell Wyse Password…
- CVE-2018-15808CRITICALCVSS 9.8EG 9.82018-08-23
POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM EVO's database may result in a breach of confidentiality, integrity, or availability or allow for attackers to remotel…
- CVE-2018-16158CRITICALCVSS 9.8EG 9.82018-08-30
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to pe…
- CVE-2018-16186HIGHCVSS 8.8EG 8.82019-01-09
RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.1 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display ver…
- CVE-2018-16201HIGHCVSS 8.8EG 8.82019-01-09
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segment to login to the administrators settings screen and chan…
- CVE-2018-1650MEDIUMCVSS 5.9EG 5.52018-12-05
IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. IBM X-Force ID: 144656.
- CVE-2018-16546MEDIUMCVSS 5.9EG 5.92018-09-05
Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another instal…
- CVE-2018-16957CRITICALCVSS 9.8EG 9.82018-09-18
The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded password. Authentication to the Oracle WCI search service uses this hardcoded password and cannot be customised by customers. …
- CVE-2018-17217HIGHCVSS 7.5EG 7.52018-10-01
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is a hardcoded encryption key.
- CVE-2018-1742MEDIUMCVSS 5.9EG 9.32018-10-08
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of …
- CVE-2018-17492HIGHCVSS 8.4EG 7.82019-03-21
EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.
- CVE-2018-17558CRITICALCVSS 9.8EG 9.82023-10-26
Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 …
- CVE-2018-17767MEDIUMCVSS 6.8EG 6.82020-09-09
Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
- CVE-2018-17771MEDIUMCVSS 6.6EG 6.62020-09-09
Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
- CVE-2018-17894CRITICALCVSS 9.8EG 9.82018-10-12
NUUO CMS all versions 3.1 and prior, The application creates default accounts that have hard-coded passwords, which could allow an attacker to gain privileged access.
- CVE-2018-17896HIGHCVSS 8.1EG 8.12018-10-12
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain…
- CVE-2018-17919MEDIUMCVSS 6.5EG 6.52018-10-10
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video streams.
- CVE-2018-18006CRITICALCVSS 9.8EG 9.82018-12-14
Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of related Google cloud printers, encrypt…
- CVE-2018-18007CRITICALCVSS 9.8EG 9.82018-12-21
atbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials.
- CVE-2018-18008CRITICALCVSS 9.8EG 9.82018-12-21
spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials.
- CVE-2018-18009CRITICALCVSS 9.8EG 9.82018-12-21
dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials.
- CVE-2018-1818MEDIUMCVSS 5.9EG 9.82018-12-13
IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IB…
- CVE-2018-18251CRITICALCVSS 9.8EG 9.82019-04-24
Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system relies on the client binary to enforce security rules and integrity of SQL statements and …
- CVE-2018-18473CRITICALCVSS 9.8EG 9.82019-03-21
A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow attackers to enable an …
- CVE-2018-1887MEDIUMCVSS 5.9EG 7.82018-12-13
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to ext…
- CVE-2018-18929HIGHCVSS 8.8EG 8.82019-10-29
The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user account in an "unattend.xml" file left over on the C: drive …
- CVE-2018-18978HIGHCVSS 7.4EG 7.42019-05-06
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption key. Extraction of the encryption key is necessary for deciphering communications between this applica…
- CVE-2018-18979HIGHCVSS 7.4EG 7.42019-05-06
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded initialization vector. Extraction of the initialization vector is necessary for deciphering communications betwee…
- CVE-2018-18998CRITICALCVSS 9.8EG 9.82019-02-05
LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high privileges.
- CVE-2018-19063CRITICALCVSS 9.8EG 9.82018-11-07
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The admin account has a blank password.
- CVE-2018-19065HIGHCVSS 7.5EG 7.52018-11-07
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The exported device configuration is e…
- CVE-2018-19066HIGHCVSS 7.5EG 7.52018-11-07
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The exported device configuration is e…
- CVE-2018-19067CRITICALCVSS 9.8EG 9.82018-11-07
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. There is a hardcoded Ak47@99 password …
- CVE-2018-19069CRITICALCVSS 9.8EG 9.82018-11-07
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The CGIProxy.fcgi?cmd=setTelnetSwitch …
- CVE-2018-19233HIGHCVSS 7.8EG 7.82018-12-20
COMPAREX Miss Marple Enterprise Edition before 2.0 allows local users to execute arbitrary code by reading the user name and encrypted password hard-coded in an Inventory Agent configuration file.
- CVE-2018-1944MEDIUMCVSS 5.1EG 9.82019-02-21
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to e…
- CVE-2018-1959MEDIUMCVSS 5.1EG 7.82019-01-24
IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption …
- CVE-2018-20219HIGHCVSS 8.1EG 8.12019-03-21
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web administration panel. Thi…
- CVE-2018-20432CRITICALCVSS 9.8EG 9.82020-09-14
D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to gain privileged access to the router, and to extract sensitive data or modify the configura…
- CVE-2018-20955CRITICALCVSS 9.8EG 9.82019-08-08
Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31.
- CVE-2018-21137CRITICALCVSS 9.8EG 9.82020-04-23
Certain NETGEAR devices are affected by a hardcoded password. This affects D3600 before 1.0.0.76 and D6000 before 1.0.0.76.
- CVE-2018-25126CRITICALCVSS 9.3EG 0.02025-11-24
Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and an OS command injection flaw in its configuration services. The web/API interface accepts…
- CVE-2018-25138CRITICALCVSS 9.8EG 7.52025-12-24
FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to mu…
- CVE-2018-4017HIGHCVSS 8.8EG 8.82019-05-13
An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam running version RoavA1SWV1.9. A set of default credentials can potentially be used to connect to the device. An attacker can connect to the AP to …
- CVE-2018-4059CRITICALCVSS 9.8EG 9.82019-03-21
An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback interface. This can pr…
- CVE-2018-4062HIGHCVSS 8.1EG 8.12019-05-06
A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a…
- CVE-2018-4846CRITICALCVSS 9.8EG 9.82018-06-26
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Sieme…
- CVE-2018-5399CRITICALCVSS 9.4EG 9.82018-10-08
The Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 22 while the DCU is running. The Dropbear server is configured with a hard-coded user name and password combination of r…
- CVE-2018-5551CRITICALCVSS 9.0EG 10.02018-03-19
Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain three credentials with known passwords: QDMaster, OTMaster, and sa.
- CVE-2018-5552LOWCVSS 2.9EG 3.32018-03-19
Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contains a hard-coded cryptographic salt, "S@l+&pepper".
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →