CWE-321: CWE-321

100
Total CVEs
34
Critical
37
High
7.8
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
10
2025
55
2024
19
2023
9
2022
3

Top Affected Vendors

1 Fortinet 3
2 Cisco 3
3 Vasion 3
4 Ivanti 2
5 Ecovacs 2
6 Dell 2
7 Ibm 2
8 Apache 2
9 Sonicwall 2
10 Advantech 2

All CWE-321 CVEs (100)

CVE-2025-46582
7.7

A low-privileged user can bypass authorization checks in ZTE's ZXMP M721 product to view the device's communication private key. This exposes cryptogr...

Oct 27, 2025
CVE-2024-56429
7.7

CVE-2024-56429 is a hard-coded cryptographic key vulnerability in iTech iLabClient 3.7.1 that allows local users to read or write to the application's...

May 21, 2025
CVE-2024-31410
7.7

CVE-2024-31410 allows attackers to impersonate any client in CyberPower PowerPanel management systems due to hard-coded cryptographic keys in device c...

May 15, 2024
CVE-2026-27519
7.5

This vulnerability in Binardat 10G08-0800GSM network switches allows attackers to decrypt protected data due to the use of RC4 encryption with a hard-...

Feb 24, 2026
CVE-2025-65998
7.5

Apache Syncope versions before 3.0.15 and 4.0.3 use a hard-coded AES encryption key for password storage when configured to encrypt passwords in the d...

Nov 24, 2025
CVE-2025-24525
7.5

Keysight Ixia Vision devices contain hardcoded cryptographic material that could allow attackers to intercept or decrypt API calls and user authentica...

Sep 30, 2025
CVE-2025-34234
7.5

Vasion Print (formerly PrinterLogic) contains hardcoded encryption keys in its application containers, allowing attackers who can access the filesyste...

Sep 29, 2025
CVE-2025-38741
7.5

Dell Enterprise SONiC OS version 4.5.0 has a cryptographic key vulnerability in SSH that allows unauthenticated remote attackers to potentially gain u...

Aug 4, 2025
CVE-2024-52881
7.5

AudioCodes OVOC versions before 8.4.582 use a hard-coded cryptographic key, allowing attackers to decrypt sensitive data like passwords from topology ...

Feb 7, 2025
CVE-2024-20350
7.5

This vulnerability allows an unauthenticated remote attacker to impersonate a Cisco Catalyst Center appliance due to a static SSH host key. Attackers ...

Sep 25, 2024
CVE-2024-20323
7.5

This vulnerability allows attackers to intercept and manipulate TLS communications between Cisco iNode Manager and intelligent nodes due to hard-coded...

Jul 17, 2024
CVE-2023-39465
7.5

Triangle MicroWorks SCADA Data Gateway contains a hard-coded cryptographic key and certificate vulnerability that allows remote attackers to decrypt s...

May 3, 2024
CVE-2023-34123
7.5

This CVE describes a hard-coded cryptographic key vulnerability in SonicWall GMS and Analytics products. Attackers who discover the embedded key could...

Jul 13, 2023
CVE-2022-1701
7.5

SonicWall SMA1000 series appliances use a shared hard-coded encryption key to store sensitive data, allowing attackers who gain access to encrypted da...

May 13, 2022
CVE-2025-55112
7.4

CVE-2025-55112 allows attackers to decrypt network traffic between Control-M/Agent and Server when Blowfish encryption is configured, due to a hardcod...

Sep 16, 2025
CVE-2024-13773
7.3

The Civi WordPress theme contains hard-coded LinkedIn API credentials in all versions up to 2.1.4, allowing unauthenticated attackers to extract sensi...

Mar 14, 2025
CVE-2023-2637
7.3

This vulnerability in Rockwell Automation's FactoryTalk System Services allows local authenticated non-admin users to generate administrator cookies u...

Jun 13, 2023
CVE-2022-23650
7.2

CVE-2022-23650 is a hard-coded cryptographic key vulnerability in Netmaker server components that allows attackers with knowledge of the admin usernam...

Feb 18, 2022
CVE-2026-2103
7.1

CVE-2026-2103 is a hard-coded cryptographic key vulnerability in Infor SyteLine ERP that allows attackers to decrypt stored credentials including pass...

Feb 6, 2026
CVE-2023-42492
7.1

EisBaer Scada uses hard-coded cryptographic keys, allowing attackers to decrypt sensitive data or forge communications. This affects all systems runni...

Oct 25, 2023
CVE-2023-34338
7.1

AMI SPx BMC firmware contains hard-coded cryptographic keys and certificates, allowing attackers to potentially decrypt sensitive data, impersonate le...

Jul 5, 2023
CVE-2025-29630
6.6

A vulnerability in Gardyn 4 allows remote attackers with the corresponding SSH private key to gain root access to affected devices. This affects all G...

Jul 25, 2025
CVE-2025-66454
6.5

Arcade MCP versions before 1.5.4 use a hardcoded default worker secret ('dev') that is never validated during server startup. This allows unauthentica...

Dec 2, 2025
CVE-2025-54471
6.5

NeuVector containers had a hard-coded cryptographic key in source code that was replaced with the actual secret key at compile time. This allows attac...

Oct 30, 2025
CVE-2025-6074
6.5

A hard-coded cryptographic key vulnerability in ABB RMC-100 and RMC-100 LITE devices allows attackers to bypass REST interface authentication when the...

Jul 3, 2025
CVE-2025-45746
6.5

CVE-2025-45746 allows unauthenticated attackers to craft valid JWT tokens using a hardcoded secret, enabling authentication bypass to the ZKT ZKBio CV...

May 13, 2025
CVE-2024-54855
6.4

Vanilla OS 2 Core image v1.1.0 contains static SSH keys, enabling attackers to perform man-in-the-middle attacks during SSH connections. This vulnerab...

Jan 13, 2026
CVE-2025-30198
6.3

ECOVACS robot vacuums and base stations use a predictable WPA2-PSK that can be easily derived, allowing attackers to join the local Wi-Fi network. Thi...

Sep 5, 2025
CVE-2024-12078
6.3

ECOVACS robot lawn mowers and vacuums use a static, shared secret key to encrypt Bluetooth Low Energy (BLE) GATT messages, allowing unauthenticated at...

Jan 23, 2025
CVE-2024-11308
6.2

CVE-2024-11308 is a hardcoded encryption key vulnerability in DVC from TRCore that allows attackers to decrypt protected files. This affects systems u...

Nov 18, 2024
CVE-2025-4876
6.0

This vulnerability allows attackers to extract a hardcoded AES decryption key from ConnectWise Risk Assessment's password encryption utility via rever...

May 19, 2025
CVE-2024-38314
5.9

IBM Maximo Application Suite Monitor Component versions 8.10, 8.11, and 9.0 contain a hard-coded cryptographic key vulnerability. This allows attacker...

Oct 24, 2024
CVE-2025-2810
5.5

CVE-2025-2810 allows a low-privileged local attacker to abuse an affected service using a hardcoded cryptographic key. This vulnerability affects syst...

Aug 5, 2025
CVE-2024-28989
5.5

SolarWinds Web Help Desk contains a hardcoded cryptographic key that could allow attackers to decrypt sensitive information stored or transmitted by t...

Feb 11, 2025
CVE-2024-45837
5.4

This vulnerability involves hard-coded cryptographic keys in AIPHONE intercom systems and software, allowing network-adjacent attackers to access SFTP...

Nov 22, 2024
CVE-2025-12177
5.3

The Download Manager WordPress plugin contains a hardcoded cron key vulnerability that allows unauthenticated attackers to trigger deletion of expired...

Nov 8, 2025
CVE-2025-35052
5.3

Newforma Info Exchange (NIX) uses a hard-coded encryption key for query parameters, allowing attackers to bypass authentication and authorization by m...

Oct 9, 2025
CVE-2025-58069
5.3

CVE-2025-58069 is a hard-coded cryptographic key vulnerability in Click Plus PLC firmware version 3.60. This allows attackers to decrypt initial sessi...

Sep 23, 2025
CVE-2025-6071
5.3

A hard-coded cryptographic key vulnerability in ABB RMC-100 and RMC-100 LITE devices allows attackers to decrypt MQTT communications. This affects spe...

Jul 3, 2025
CVE-2024-46889
5.3

SINEC INS versions before V1.0 SP2 Update 3 use hard-coded cryptographic keys to obfuscate configuration files, allowing attackers to reverse-engineer...

Nov 12, 2024
CVE-2025-56802
5.1

The Reolink desktop application uses a predictable AES encryption key to protect user configuration files, allowing attackers with local system access...

Oct 21, 2025
CVE-2025-56801
5.1

The Reolink Desktop Application uses predictable initialization vectors in its AES-CFB encryption, potentially allowing attackers with local access to...

Oct 21, 2025
CVE-2025-34211
4.9

Vasion Print (formerly PrinterLogic) appliances contain a hardcoded private SSL key and matching certificate stored in cleartext. This allows attacker...

Sep 29, 2025
CVE-2025-14923
4.7

IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.2 have a security weakness in the Security Utility that could allow reduced ...

Mar 3, 2026
CVE-2025-52373
4.6

This vulnerability involves a hardcoded cryptographic key in hMailServer that allows attackers to decrypt database passwords stored in the hMailServer...

Jul 21, 2025
CVE-2025-58426
4.3

This vulnerability in desknet's NEO software involves a hard-coded cryptographic key that could allow attackers to create malicious AppSuite applicati...

Oct 16, 2025
CVE-2025-49164
4.3

Arris VIP1113 devices have a hardcoded firmware decryption key in the KreaTV SDK, allowing attackers to decrypt and potentially modify firmware. This ...

Jun 3, 2025
CVE-2024-33504
4.1

This vulnerability in FortiManager allows attackers with JSON API access permissions to decrypt sensitive data due to hard-coded cryptographic keys. I...

Feb 11, 2025
CVE-2025-64304
4.0

The 'FOD' app uses hard-coded cryptographic keys, allowing local unauthenticated attackers to extract these keys. This vulnerability affects users of ...

Nov 25, 2025
CVE-2024-52614
4.0

The Kura Sushi Official App for Android versions before 3.8.5 contains a hard-coded cryptographic key vulnerability. This allows local attackers to po...

Nov 20, 2024

About CWE-321 (CWE-321)

Our database tracks 100 CVEs classified as CWE-321, with 34 rated critical and 37 rated high severity. The average CVSS score for CWE-321 vulnerabilities is 7.8.

External reference: View CWE-321 on MITRE CWE →

Monitor CWE-321 Vulnerabilities

Get alerted when new CWE-321 CVEs affect your infrastructure.

Start Monitoring Free