CWE-798: CWE-798
Yearly Trend
Top Affected Vendors
All CWE-798 CVEs (444)
All Wattsense Bridge devices contain hard-coded credentials in their firmware, allowing attackers to gain root access via the serial interface. This a...
Feb 11, 2025This CVE describes a use of hard-coded credentials vulnerability in multiple ABB industrial control system products. Attackers can use these embedded ...
Feb 6, 2025This vulnerability allows remote attackers to generate valid JWT tokens using a hardcoded weak secret, enabling privilege escalation in affected EasyV...
Jan 31, 2025The HI-SCAN 6040i Hitrax HX-03-19-I security scanner contains hardcoded credentials that provide vendor support and service access. This allows attack...
Jan 15, 2025CVE-2024-55557 is a critical vulnerability in Weasis 4.5.1 where proxy credentials are encrypted using a hardcoded symmetric key. This allows attacker...
Dec 16, 2024Ubiquiti U6-LR access points running firmware version 6.6.65 contain a hardcoded root password in the /etc/shadow file, allowing attackers to gain ful...
Dec 6, 2024This vulnerability allows remote attackers to bypass authentication on Allegra installations by exploiting hard-coded database credentials. Attackers ...
Nov 22, 2024CVE-2024-52295 is a critical authentication bypass vulnerability in DataEase where attackers can forge JWT tokens due to hardcoded secrets and identif...
Nov 13, 2024LB-LINK BL-WR 1300H router firmware version 1.0.4 contains hardcoded credentials stored in the /etc/shadow file that are easily guessable. This allows...
Nov 1, 2024IBM Flexible Service Processor (FSP) firmware contains hardcoded credentials that could allow network users to gain service privileges. This affects m...
Oct 29, 2024This vulnerability allows attackers to gain root access to Kubernetes nodes using default credentials that remain enabled in VM images built with Kube...
Oct 15, 2024CVE-2024-6656 is a critical vulnerability in TNB Mobile Solutions Cockpit Software where hard-coded credentials allow attackers to extract sensitive s...
Sep 13, 2024This critical vulnerability in TOTOLINK T10 AC1200 routers involves hard-coded credentials in the Telnet service configuration file, allowing remote a...
Aug 26, 2024H3C R3010 routers running version v100R002L02 contain a hardcoded root password in /etc/shadow, allowing attackers to gain complete administrative con...
Aug 16, 2024D-Link DIR-300 REVA routers running firmware v1.06B05_WW contain hardcoded credentials in their Telnet service, allowing attackers to gain administrat...
Aug 6, 2024This vulnerability allows attackers to remotely access D-Link DIR-820LW routers via Telnet using hardcoded credentials. Attackers can execute arbitrar...
Jul 30, 2024This vulnerability involves hard-coded MSSQL credentials in PerkinElmer ProcessPlus software on Windows, allowing attackers to remotely authenticate t...
Jul 22, 2024CVE-2024-28747 allows unauthenticated remote attackers to access SmartSPS devices using hard-coded credentials with high privileges. This affects all ...
Jul 9, 2024CVE-2024-39208 is a critical vulnerability in luci-app-lucky v2.8.3 that contains hardcoded credentials, allowing attackers to bypass authentication a...
Jun 27, 2024TELSAT marKoni FM Transmitters contain a hidden admin account with hard-coded credentials, allowing attackers to gain administrative access. This affe...
Jun 27, 2024CVE-2024-36480 is a critical vulnerability in Ricoh Streamline NX PC Client versions 3.7.2 and earlier that uses hard-coded credentials. If exploited,...
Jun 19, 2024Shenzhen Guoxin Synthesis image systems before version 8.3.0 have a hardcoded default password '123456Qw' that cannot be changed by users. This allows...
Jun 16, 2024This vulnerability allows attackers to access the maintenance console of affected devices using hard-coded credentials for a hidden wireless network. ...
Jun 13, 2024CVE-2024-3408 is a critical vulnerability in dtale versions 3.10.0 that allows attackers to bypass authentication and execute arbitrary code on the se...
Jun 6, 2024This vulnerability allows attackers to gain root access to TOTOLINK CP300 routers by using a hardcoded password found in a sample configuration file. ...
Jun 3, 2024MinMax CMS contains a hidden administrator account with a fixed, unchangeable password that cannot be removed or disabled. Remote attackers who discov...
May 30, 2024This vulnerability involves a hardcoded root password in the TOTOLINK CP900L router's configuration file, allowing attackers to gain administrative ac...
May 24, 2024This vulnerability involves undocumented users with hardcoded credentials in SIMATIC CN 4100 devices. Attackers can use these credentials to gain unau...
May 14, 2024This vulnerability involves a hardcoded root password in TOTOLINK EX200 routers, allowing attackers to gain administrative access. Anyone using affect...
May 14, 2024This vulnerability allows remote attackers to bypass authentication on D-Link D-View systems by exploiting hard-coded database credentials in the Inst...
May 3, 2024This vulnerability in D-Link network storage devices allows remote attackers to access hard-coded credentials via HTTP GET requests to the nas_sharing...
Apr 4, 2024This vulnerability involves hard-coded credentials in Kiloview NDI devices, allowing unauthenticated attackers to bypass authentication and gain unaut...
Mar 21, 2024The INPRAX 'iZZi connect' Android application contains hard-coded MQTT queue credentials that are shared with physical recuperation devices. This allo...
Feb 15, 2024This vulnerability allows unauthenticated remote attackers to gain full administrative access to Siemens Location Intelligence products by exploiting ...
Feb 13, 2024This vulnerability in SCHUHFRIED v.8.22.00 allows remote attackers to retrieve the database password without authentication via a crafted curl command...
Feb 7, 2024This vulnerability allows remote attackers to gain root access to D-LINK Go-RT-AC750 routers via telnet using a hardcoded password for the Alphanetwor...
Feb 6, 2024Rapid SCADA versions before 5.8.4 contain hard-coded credentials that allow attackers to connect to a specific port. This affects all users running vu...
Feb 2, 2024Gessler GmbH WEB-MASTER devices contain a restoration account with hard-coded credentials that cannot be changed. If exploited, attackers can gain adm...
Feb 1, 2024The TOTOLINK A8000RU router version 7.1cu.643_B20200521 contains a hardcoded root password in the /etc/shadow file, allowing attackers to gain adminis...
Jan 30, 2024IBM Merge Healthcare eFilm Workstation contains hardcoded credentials that allow remote unauthenticated attackers to access the system. This vulnerabi...
Jan 26, 2024Multisuns EasyLog web+ uses hard-coded credentials that allow remote attackers to gain unauthorized access. This vulnerability enables attackers to pe...
Dec 15, 2023NETSCOUT nGeniusPULSE 3.8 contains a hardcoded cryptographic key, allowing attackers to decrypt sensitive data or bypass authentication. This affects ...
Dec 7, 2023CVE-2023-23324 involves hardcoded administrator credentials in Zumtobel Netlink CCD Onboard firmware versions 3.74-3.80. This allows attackers to gain...
Nov 29, 2023First Corporation DVRs contain a hard-coded password vulnerability that allows remote unauthenticated attackers to access and modify device configurat...
Nov 16, 2023This vulnerability allows remote attackers to execute arbitrary code on Natus NeuroWorks and SleepWorks systems due to a default hardcoded password 'x...
Nov 10, 2023This vulnerability in Weintek EasyBuilder Pro exposes private keys during crash report transmission, allowing attackers to potentially gain remote con...
Nov 6, 2023CVE-2023-31579 is a critical authentication bypass vulnerability in Dromara Lamp-Cloud where hardcoded JWT signing keys allow attackers to forge valid...
Nov 2, 2023This CVE describes two critical vulnerabilities in ABUS security cameras: hardcoded manufacturer credentials and an OS command injection flaw in the /...
Oct 26, 2023CVE-2023-31581 is a critical authentication bypass vulnerability in Dromara Sureness security framework versions before 1.0.8. The vulnerability allow...
Oct 25, 2023This vulnerability allows attackers with knowledge of a hard-coded SSH private key to gain unauthorized access to Siemens CP-8031 and CP-8050 MASTER M...
Oct 10, 2023About CWE-798 (CWE-798)
Our database tracks 444 CVEs classified as CWE-798, with 253 rated critical and 143 rated high severity. The average CVSS score for CWE-798 vulnerabilities is 8.8.
External reference: View CWE-798 on MITRE CWE →
Monitor CWE-798 Vulnerabilities
Get alerted when new CWE-798 CVEs affect your infrastructure.
Start Monitoring Free