CWE-798— Use of Hard-coded Credentials
1,580 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 7 of 32
- CVE-2019-20025CRITICALCVSS 9.8EG 9.82020-07-29
Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password, aka a Static Credential Vulnerability. The vulnerability is due …
- CVE-2019-20471HIGHCVSS 7.8EG 7.82021-02-01
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup, a default password is used (123456) for administrative purposes. There is no prompt to change this password. Note that…
- CVE-2019-20656HIGHCVSS 8.8EG 8.82020-04-15
Certain NETGEAR devices are affected by a hardcoded password. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.74, PR2000 before 1.0.0.30, R6020 before 1.0.0.42, R6080 before 1.0.0.42, R6050 before 1.0.1.24, JR6150 before 1.0.1.24, …
- CVE-2019-25021HIGHCVSS 7.5EG 7.52021-02-27
An issue was discovered in Scytl sVote 2.1. Due to the implementation of the database manager, an attacker can access the OrientDB by providing admin as the admin password. A different password cannot be set because of the implementation i…
- CVE-2019-25241CRITICALCVSS 9.8EG 7.52025-12-24
FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root…
- CVE-2019-25291HIGHCVSS 7.5EG 7.52026-01-08
INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain…
- CVE-2019-25322HIGHCVSS 7.5EG 7.52026-02-12
Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' i…
- CVE-2019-25722HIGHCVSS 7.6EG 7.62026-06-02
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denial-of-service vulnerability that allows local and remote attackers to compromise device in…
- CVE-2019-3495HIGHCVSS 8.8EG 8.82019-03-21
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, allowing an attacker to upload .php files and execute code on the server with root user privi…
- CVE-2019-3496HIGHCVSS 8.8EG 8.82019-03-21
An issue was discovered on Wifi-soft UniBox controller 3.x devices. The tools/controller/diagnostic_tools_controller Diagnostic Tools Controller is vulnerable to Remote Command Execution, allowing an attacker to execute arbitrary system co…
- CVE-2019-3497HIGHCVSS 8.8EG 8.82019-03-21
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. The tools/ping Ping feature of the Diagnostic Tools component is vulnerable to Remote Command Execution, allowing an attacker to execute arbitrary system comma…
- CVE-2019-3710HIGHCVSS 8.1EG 8.12019-03-28
Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying application using undocumented, pre-installed X.509v3 key/certificate pairs. An unauthenticated remote attacker with the knowl…
- CVE-2019-3906HIGHCVSS 8.8EG 8.82019-01-18
Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents.
- CVE-2019-3907HIGHCVSS 7.5EG 7.52019-01-18
Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).
- CVE-2019-3908HIGHCVSS 7.5EG 7.52019-01-18
Premisys Identicard version 3.1.190 stores backup files as encrypted zip files. The password to the zip is hard-coded and unchangeable. An attacker with access to these backups can decrypt them and obtain sensitive data.
- CVE-2019-3918CRITICALCVSS 9.8EG 9.82019-03-05
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces.
- CVE-2019-3932CRITICALCVSS 9.8EG 9.82019-04-30
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated attacker can use this vulnerability to control external de…
- CVE-2019-3938HIGHCVSS 7.8EG 7.82019-04-30
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file generated via the "export configuration" feature. The configuration file is encrypted using the…
- CVE-2019-3939CRITICALCVSS 9.8EG 9.82019-04-30
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use these credentials to gain privileged acce…
- CVE-2019-3950CRITICALCVSS 9.8EG 9.82019-07-09
Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to.
- CVE-2019-3983MEDIUMCVSS 6.8EG 6.82019-12-11
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections.
- CVE-2019-4220MEDIUMCVSS 5.5EG 5.52019-06-06
IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force ID: 159229.
- CVE-2019-4309MEDIUMCVSS 5.5EG 5.52019-10-29
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to obtain highly sensitive information. IBM X-Force ID: 161035.
- CVE-2019-4327HIGHCVSS 7.5EG 7.52020-04-21
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
- CVE-2019-4392CRITICALCVSS 9.8EG 9.82020-02-14
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.
- CVE-2019-4675CRITICALCVSS 9.8EG 9.82020-02-04
IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. …
- CVE-2019-4694CRITICALCVSS 9.8EG 9.82020-08-26
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of…
- CVE-2019-5021CRITICALCVSS 9.8EG 9.82019-05-08
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, syst…
- CVE-2019-5106MEDIUMCVSS 5.5EG 5.52020-03-11
A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of a…
- CVE-2019-5137HIGHCVSS 7.5EG 7.52020-02-25
The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.
- CVE-2019-5139HIGHCVSS 7.1EG 7.12020-02-25
An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation o…
- CVE-2019-5158HIGHCVSS 7.8EG 7.82020-03-11
An exploitable firmware downgrade vulnerability exists in the firmware update package functionality of the WAGO e!COCKPIT automation software v1.6.1.5. A specially crafted firmware update file can allow an attacker to install an older firm…
- CVE-2019-5622CRITICALCVSS 9.8EG 9.82020-04-29
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-798: Use of Hard-coded Credentials.
- CVE-2019-6499HIGHCVSS 8.1EG 8.12019-01-21
Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could potentially be exploited by malicious users to compromise th…
- CVE-2019-6548CRITICALCVSS 9.8EG 9.82019-05-09
GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if Windows default firewall settings are used b…
- CVE-2019-6572CRITICALCVSS 9.1EG 9.12019-05-14
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15.1 Update 1), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F…
- CVE-2019-6693MEDIUMCVSS 6.5EG 9.0⚠ KEV2019-11-21
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementione…
- CVE-2019-6698CRITICALCVSS 9.8EG 9.82019-08-23
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provi…
- CVE-2019-6725CRITICALCVSS 9.8EG 9.82019-05-31
The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and the interface of t…
- CVE-2019-6812HIGHCVSS 7.2EG 7.22019-05-22
A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 which could cause a confidentiality issue when using FTP protocol.
- CVE-2019-6859HIGHCVSS 7.5EG 7.52020-04-22
A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of …
- CVE-2019-7161HIGHCVSS 7.5EG 7.52019-03-21
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.
- CVE-2019-7212HIGHCVSS 8.2EG 8.22019-04-24
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.
- CVE-2019-7225HIGHCVSS 8.8EG 8.82019-06-27
The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface and Tags (MODBUS c…
- CVE-2019-7261CRITICALCVSS 9.8EG 9.82019-07-02
Linear eMerge E3-Series devices have Hard-coded Credentials.
- CVE-2019-7265CRITICALCVSS 9.8EG 9.82019-07-02
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
- CVE-2019-7279HIGHCVSS 7.3EG 7.32019-07-01
Optergy Proton/Enterprise devices have Hard-coded Credentials.
- CVE-2019-7593MEDIUMCVSS 6.8EG 9.12019-08-20
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).
- CVE-2019-7594MEDIUMCVSS 6.8EG 9.12019-08-20
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).
- CVE-2019-7672HIGHCVSS 8.8EG 8.82019-06-05
Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow an authenticated attacker to escalate privileges.
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →