CWE-798: CWE-798

451
Total CVEs
258
Critical
145
High
8.8
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
24
2025
100
2024
97
2023
66
2022
69

Top Affected Vendors

1 Ibm 19
2 Fiberhome 15
3 Dlink 14
4 Totolink 7
5 Siemens 6
6 Schneider Electric 6
7 Solarwinds 5
8 Fortinet 4
9 Tenda 4
10 Dell 4

All CWE-798 CVEs (451)

CVE-2026-22769
10.0

Dell RecoverPoint for Virtual Machines versions before 6.0.3.1 HF1 contain hardcoded credentials that allow unauthenticated remote attackers to gain r...

Feb 17, 2026
CVE-2025-42890
10.0

SQL Anywhere Monitor (Non-GUI) contains hardcoded credentials that allow attackers to bypass authentication and execute arbitrary code. This affects a...

Nov 11, 2025
CVE-2025-20309
10.0

This critical vulnerability allows unauthenticated remote attackers to log into Cisco Unified Communications Manager systems using static root credent...

Jul 2, 2025
CVE-2025-48748
10.0

Netwrix Directory Manager (formerly Imanami GroupID) versions through 10.0.7784.0 contain a hard-coded password vulnerability. This allows attackers t...

May 29, 2025
CVE-2025-20188
10.0

This critical vulnerability in Cisco IOS XE Wireless LAN Controllers allows unauthenticated remote attackers to upload arbitrary files and execute com...

May 7, 2025
CVE-2024-41794
10.0

SENTRON 7KT PAC1260 Data Manager devices contain hardcoded root credentials that allow unauthenticated remote attackers to gain full system access whe...

Apr 8, 2025
CVE-2024-42450
10.0

This vulnerability allows unauthenticated attackers to access PostgreSQL databases in Versa Director installations due to default weak credentials and...

Nov 19, 2024
CVE-2023-2306
10.0

Qognify NiceVision versions 3.1 and prior contain hard-coded credentials that allow attackers to access sensitive information and modify database reco...

Oct 5, 2023
CVE-2021-40422
10.0

CVE-2021-40422 is an authentication bypass vulnerability in Swift Sensors Gateway SG3-1010 that allows remote attackers to execute arbitrary code with...

Apr 14, 2022
CVE-2021-40519
10.0

Airangel HSMX Gateway devices through version 5.2.04 contain hard-coded database credentials, allowing attackers to gain unauthorized access to the de...

Nov 10, 2021
CVE-2021-0248
10.0

This vulnerability involves hard-coded credentials in Juniper Junos OS on NFX Series devices, allowing attackers to take over any NFX deployment insta...

Apr 22, 2021
CVE-2020-6779
10.0

This CVE involves hard-coded credentials in Bosch FSM server databases, allowing unauthenticated remote attackers to gain admin access. This can lead ...

Jan 26, 2021
CVE-2026-27507
9.8

Binardat 10G08-0800GSM network switches contain hard-coded administrative credentials that cannot be changed, allowing attackers with knowledge of the...

Feb 24, 2026
CVE-2026-23647
9.8

CVE-2026-23647 allows attackers to remotely authenticate to Glory RBG-100 recycler systems using hard-coded Linux credentials, including administrativ...

Feb 17, 2026
CVE-2026-26218
9.8

CVE-2026-26218 allows unauthenticated attackers to gain administrative control of newbee-mall applications by using predictable default passwords on p...

Feb 12, 2026
CVE-2026-25803
9.8

3DP-MANAGER versions 2.0.1 and earlier automatically create an administrative account with default credentials (admin/admin) on first initialization. ...

Feb 6, 2026
CVE-2025-69971
9.8

FUXA v1.2.7 contains a hard-coded JWT secret key that allows attackers to forge valid authentication tokens. This enables complete authentication bypa...

Feb 3, 2026
CVE-2026-25202
9.8

MagicINFO 9 Server versions below 21.1090.1 contain hardcoded database credentials, allowing attackers to authenticate and manipulate the database. Th...

Feb 2, 2026
CVE-2023-53983
9.8

CVE-2023-53983 allows attackers to gain full administrative control of Anevia Flamingo XL/XS devices by exploiting weak default credentials. This affe...

Dec 30, 2025
CVE-2022-50696
9.8

SOUND4 IMPACT/FIRST/PULSE/Eco devices versions 2.x and below contain hardcoded credentials in server binaries that cannot be changed through normal op...

Dec 30, 2025
CVE-2025-67418
9.8

ClipBucket 5.5.2 ships with hardcoded default administrative credentials, allowing unauthenticated remote attackers to gain full administrative contro...

Dec 22, 2025
CVE-2025-56157
9.8

CVE-2025-56157 exposes Dify installations to unauthorized database access through hardcoded PostgreSQL credentials in docker-compose.yaml. Attackers c...

Dec 18, 2025
CVE-2025-36752
9.8

The Growatt ShineLan-X communication dongle contains an undocumented backup account with hardcoded credentials, creating a backdoor that allows attack...

Dec 13, 2025
CVE-2025-36747
9.8

CVE-2025-36747 is a critical vulnerability in ShineLan-X firmware where hardcoded FTP credentials allow attackers to establish insecure connections. T...

Dec 13, 2025
CVE-2025-14611
KEV EPSS 57.4% 9.8

This vulnerability in Gladinet CentreStack and Triofox involves hardcoded AES encryption keys, allowing attackers to decrypt sensitive data and potent...

Dec 12, 2025
CVE-2025-65823
9.8

The Meatmeet Pro device contains hardcoded Wi-Fi credentials in its firmware, allowing attackers to gain unauthorized access to the vendor's Wi-Fi net...

Dec 10, 2025
CVE-2025-29268
9.8

ALLNET ALL-RUT22GW routers contain hardcoded credentials in the libicos.so library, allowing attackers to gain unauthorized access to the device. This...

Dec 4, 2025
CVE-2025-10850
9.8

The Felan Framework WordPress plugin contains hardcoded passwords in social login functions, allowing unauthenticated attackers to log in as any user ...

Oct 16, 2025
CVE-2025-57601
9.8

This vulnerability allows attackers who obtain the hardcoded SSH private key to impersonate any managed IoT/edge device in AiKaan Cloud Controller env...

Sep 22, 2025
CVE-2025-34198
9.8

Vasion Print (formerly PrinterLogic) appliances use the same hardcoded SSH host private keys across all installations instead of unique per-appliance ...

Sep 19, 2025
CVE-2025-8570
9.8

The BeyondCart Connector WordPress plugin has a critical privilege escalation vulnerability in versions 1.4.2 through 2.1.0. Unauthenticated attackers...

Sep 11, 2025
CVE-2025-35452
9.8

This vulnerability allows attackers to access PTZOptics and other ValueHD-based pan-tilt-zoom cameras using default, shared administrative credentials...

Sep 5, 2025
CVE-2025-35451
9.8

This vulnerability affects PTZOptics and other ValueHD-based pan-tilt-zoom cameras that use hard-coded default administrative credentials that cannot ...

Sep 5, 2025
CVE-2025-8857
9.8

Clinic Image System contains hard-coded administrator credentials in its source code, allowing unauthenticated remote attackers to gain full system ac...

Aug 29, 2025
CVE-2025-51536
9.8

OpenAtlas v8.11.0 contains a hardcoded administrator password, allowing attackers to gain full administrative access to the system. This affects all d...

Aug 4, 2025
CVE-2025-30125
9.8

Marbella KR8s Dashcam FF 2.0.8 devices ship with a universal default password (12345678) that cannot be changed to a strong password (limited to 8 cha...

Jul 28, 2025
CVE-2025-7401
9.8

This vulnerability in the Premium Age Verification WordPress plugin allows unauthenticated attackers to read or write arbitrary files on the server th...

Jul 11, 2025
CVE-2025-37103
9.8

CVE-2025-37103 is a critical authentication bypass vulnerability in HPE Networking Instant On Access Points where hard-coded credentials allow attacke...

Jul 8, 2025
CVE-2025-45813
9.8

ENENSYS IPGuard v2 2.10.0 contains hardcoded credentials that could allow attackers to gain unauthorized access to the system. This affects all deploy...

Jul 2, 2025
CVE-2025-45784
9.8

D-Link DPH-400S/SE VoIP phones contain hardcoded provisioning credentials in their firmware, allowing attackers who obtain the firmware image to extra...

Jun 18, 2025
CVE-2025-28388
9.8

OpenC3 COSMOS versions before v6.0.2 contain hardcoded credentials for a Service Account, allowing attackers to gain unauthorized access to the system...

Jun 13, 2025
CVE-2025-46352
9.8

The CS5000 Fire Panel contains a hard-coded VNC password that cannot be changed, allowing attackers with knowledge of this password to gain remote adm...

May 30, 2025
CVE-2025-32985
9.8

NETSCOUT nGeniusONE versions before 6.4.0 b2350 contain hardcoded credentials within JAR files that can be extracted by attackers. This allows unautho...

Apr 25, 2025
CVE-2025-46273
9.8

CVE-2025-46273 is a critical vulnerability in UNI-NMS-Lite network management software where hard-coded administrative credentials allow unauthenticat...

Apr 24, 2025
CVE-2025-2538
9.8

A hardcoded credential vulnerability in Esri Portal for ArcGIS versions 11.4 and below allows remote unauthenticated attackers to gain administrative ...

Mar 20, 2025
CVE-2025-30137
9.8

This vulnerability allows attackers to gain unauthorized access to G-Net GNET dashcam systems using hardcoded credentials found in the mobile applicat...

Mar 18, 2025
CVE-2025-30122
9.8

ROADCAM X3 devices have hardcoded default credentials that cannot be changed by users, allowing attackers to gain unauthorized administrative access. ...

Mar 18, 2025
CVE-2025-30113
9.8

The Forvia Hella HELLA Driving Recorder DR 820 dashcam's Android application contains hardcoded credentials that allow unauthorized access to device s...

Mar 18, 2025
CVE-2025-1393
9.8

This vulnerability allows unauthenticated remote attackers to gain full administrative control over affected systems using hard-coded credentials. Any...

Mar 5, 2025
CVE-2024-57040
9.8

This vulnerability involves hardcoded root passwords in specific TP-Link router firmware versions, allowing attackers to gain administrative access. A...

Feb 26, 2025

About CWE-798 (CWE-798)

Our database tracks 451 CVEs classified as CWE-798, with 258 rated critical and 145 rated high severity. The average CVSS score for CWE-798 vulnerabilities is 8.8.

External reference: View CWE-798 on MITRE CWE →

Monitor CWE-798 Vulnerabilities

Get alerted when new CWE-798 CVEs affect your infrastructure.

Start Monitoring Free