CWE-798: CWE-798

444
Total CVEs
253
Critical
143
High
8.8
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
24
2025
100
2024
97
2023
66
2022
69

Top Affected Vendors

1 Ibm 18
2 Fiberhome 15
3 Dlink 13
4 Totolink 7
5 Schneider Electric 6
6 Siemens 6
7 Solarwinds 5
8 Fortinet 4
9 Tenda 4
10 Dell 4

All CWE-798 CVEs (444)

CVE-2025-26410
9.8

All Wattsense Bridge devices contain hard-coded credentials in their firmware, allowing attackers to gain root access via the serial interface. This a...

Feb 11, 2025
CVE-2024-51547
9.8

This CVE describes a use of hard-coded credentials vulnerability in multiple ABB industrial control system products. Attackers can use these embedded ...

Feb 6, 2025
CVE-2024-53356
9.8

This vulnerability allows remote attackers to generate valid JWT tokens using a hardcoded weak secret, enabling privilege escalation in affected EasyV...

Jan 31, 2025
CVE-2024-48126
9.8

The HI-SCAN 6040i Hitrax HX-03-19-I security scanner contains hardcoded credentials that provide vendor support and service access. This allows attack...

Jan 15, 2025
CVE-2024-55557
9.8

CVE-2024-55557 is a critical vulnerability in Weasis 4.5.1 where proxy credentials are encrypted using a hardcoded symmetric key. This allows attacker...

Dec 16, 2024
CVE-2024-54750
9.8

Ubiquiti U6-LR access points running firmware version 6.6.65 contain a hardcoded root password in the /etc/shadow file, allowing attackers to gain ful...

Dec 6, 2024
CVE-2023-51638
9.8

This vulnerability allows remote attackers to bypass authentication on Allegra installations by exploiting hard-coded database credentials. Attackers ...

Nov 22, 2024
CVE-2024-52295
9.8

CVE-2024-52295 is a critical authentication bypass vulnerability in DataEase where attackers can forge JWT tokens due to hardcoded secrets and identif...

Nov 13, 2024
CVE-2024-51431
9.8

LB-LINK BL-WR 1300H router firmware version 1.0.4 contains hardcoded credentials stored in the /etc/shadow file that are easily guessable. This allows...

Nov 1, 2024
CVE-2024-45656
9.8

IBM Flexible Service Processor (FSP) firmware contains hardcoded credentials that could allow network users to gain service privileges. This affects m...

Oct 29, 2024
CVE-2024-9486
9.8

This vulnerability allows attackers to gain root access to Kubernetes nodes using default credentials that remain enabled in VM images built with Kube...

Oct 15, 2024
CVE-2024-6656
9.8

CVE-2024-6656 is a critical vulnerability in TNB Mobile Solutions Cockpit Software where hard-coded credentials allow attackers to extract sensitive s...

Sep 13, 2024
CVE-2024-8162
9.8

This critical vulnerability in TOTOLINK T10 AC1200 routers involves hard-coded credentials in the Telnet service configuration file, allowing remote a...

Aug 26, 2024
CVE-2024-42637
9.8

H3C R3010 routers running version v100R002L02 contain a hardcoded root password in /etc/shadow, allowing attackers to gain complete administrative con...

Aug 16, 2024
CVE-2024-41616
9.8

D-Link DIR-300 REVA routers running firmware v1.06B05_WW contain hardcoded credentials in their Telnet service, allowing attackers to gain administrat...

Aug 6, 2024
CVE-2024-41610
9.8

This vulnerability allows attackers to remotely access D-Link DIR-820LW routers via Telnet using hardcoded credentials. Attackers can execute arbitrar...

Jul 30, 2024
CVE-2024-6912
9.8

This vulnerability involves hard-coded MSSQL credentials in PerkinElmer ProcessPlus software on Windows, allowing attackers to remotely authenticate t...

Jul 22, 2024
CVE-2024-28747
9.8

CVE-2024-28747 allows unauthenticated remote attackers to access SmartSPS devices using hard-coded credentials with high privileges. This affects all ...

Jul 9, 2024
CVE-2024-39208
9.8

CVE-2024-39208 is a critical vulnerability in luci-app-lucky v2.8.3 that contains hardcoded credentials, allowing attackers to bypass authentication a...

Jun 27, 2024
CVE-2024-39374
9.8

TELSAT marKoni FM Transmitters contain a hidden admin account with hard-coded credentials, allowing attackers to gain administrative access. This affe...

Jun 27, 2024
CVE-2024-36480
9.8

CVE-2024-36480 is a critical vulnerability in Ricoh Streamline NX PC Client versions 3.7.2 and earlier that uses hard-coded credentials. If exploited,...

Jun 19, 2024
CVE-2024-38466
9.8

Shenzhen Guoxin Synthesis image systems before version 8.3.0 have a hardcoded default password '123456Qw' that cannot be changed by users. This allows...

Jun 16, 2024
CVE-2024-38281
9.8

This vulnerability allows attackers to access the maintenance console of affected devices using hard-coded credentials for a hidden wireless network. ...

Jun 13, 2024
CVE-2024-3408
9.8

CVE-2024-3408 is a critical vulnerability in dtale versions 3.10.0 that allows attackers to bypass authentication and execute arbitrary code on the se...

Jun 6, 2024
CVE-2024-36782
9.8

This vulnerability allows attackers to gain root access to TOTOLINK CP300 routers by using a hardcoded password found in a sample configuration file. ...

Jun 3, 2024
CVE-2024-5514
9.8

MinMax CMS contains a hidden administrator account with a fixed, unchangeable password that cannot be removed or disabled. Remote attackers who discov...

May 30, 2024
CVE-2024-35396
9.8

This vulnerability involves a hardcoded root password in the TOTOLINK CP900L router's configuration file, allowing attackers to gain administrative ac...

May 24, 2024
CVE-2024-32740
9.8

This vulnerability involves undocumented users with hardcoded credentials in SIMATIC CN 4100 devices. Attackers can use these credentials to gain unau...

May 14, 2024
CVE-2024-31810
9.8

This vulnerability involves a hardcoded root password in TOTOLINK EX200 routers, allowing attackers to gain administrative access. Anyone using affect...

May 14, 2024
CVE-2023-44411
9.8

This vulnerability allows remote attackers to bypass authentication on D-Link D-View systems by exploiting hard-coded database credentials in the Inst...

May 3, 2024
CVE-2024-3272
9.8

This vulnerability in D-Link network storage devices allows remote attackers to access hard-coded credentials via HTTP GET requests to the nas_sharing...

Apr 4, 2024
CVE-2024-2161
9.8

This vulnerability involves hard-coded credentials in Kiloview NDI devices, allowing unauthenticated attackers to bypass authentication and gain unaut...

Mar 21, 2024
CVE-2024-0390
9.8

The INPRAX 'iZZi connect' Android application contains hard-coded MQTT queue credentials that are shared with physical recuperation devices. This allo...

Feb 15, 2024
CVE-2024-23816
9.8

This vulnerability allows unauthenticated remote attackers to gain full administrative access to Siemens Location Intelligence products by exploiting ...

Feb 13, 2024
CVE-2023-38995
9.8

This vulnerability in SCHUHFRIED v.8.22.00 allows remote attackers to retrieve the database password without authentication via a crafted curl command...

Feb 7, 2024
CVE-2024-22853
9.8

This vulnerability allows remote attackers to gain root access to D-LINK Go-RT-AC750 routers via telnet using a hardcoded password for the Alphanetwor...

Feb 6, 2024
CVE-2024-21764
9.8

Rapid SCADA versions before 5.8.4 contain hard-coded credentials that allow attackers to connect to a specific port. This affects all users running vu...

Feb 2, 2024
CVE-2024-1039
9.8

Gessler GmbH WEB-MASTER devices contain a restoration account with hard-coded credentials that cannot be changed. If exploited, attackers can gain adm...

Feb 1, 2024
CVE-2024-24324
9.8

The TOTOLINK A8000RU router version 7.1cu.643_B20200521 contains a hardcoded root password in the /etc/shadow file, allowing attackers to gain adminis...

Jan 30, 2024
CVE-2024-23619
9.8

IBM Merge Healthcare eFilm Workstation contains hardcoded credentials that allow remote unauthenticated attackers to access the system. This vulnerabi...

Jan 26, 2024
CVE-2023-48388
9.8

Multisuns EasyLog web+ uses hard-coded credentials that allow remote attackers to gain unauthorized access. This vulnerability enables attackers to pe...

Dec 15, 2023
CVE-2023-40300
9.8

NETSCOUT nGeniusPULSE 3.8 contains a hardcoded cryptographic key, allowing attackers to decrypt sensitive data or bypass authentication. This affects ...

Dec 7, 2023
CVE-2023-23324
9.8

CVE-2023-23324 involves hardcoded administrator credentials in Zumtobel Netlink CCD Onboard firmware versions 3.74-3.80. This allows attackers to gain...

Nov 29, 2023
CVE-2023-47213
9.8

First Corporation DVRs contain a hard-coded password vulnerability that allows remote unauthenticated attackers to access and modify device configurat...

Nov 16, 2023
CVE-2023-47800
9.8

This vulnerability allows remote attackers to execute arbitrary code on Natus NeuroWorks and SleepWorks systems due to a default hardcoded password 'x...

Nov 10, 2023
CVE-2023-5777
9.8

This vulnerability in Weintek EasyBuilder Pro exposes private keys during crash report transmission, allowing attackers to potentially gain remote con...

Nov 6, 2023
CVE-2023-31579
9.8

CVE-2023-31579 is a critical authentication bypass vulnerability in Dromara Lamp-Cloud where hardcoded JWT signing keys allow attackers to forge valid...

Nov 2, 2023
CVE-2018-17558
9.8

This CVE describes two critical vulnerabilities in ABUS security cameras: hardcoded manufacturer credentials and an OS command injection flaw in the /...

Oct 26, 2023
CVE-2023-31581
9.8

CVE-2023-31581 is a critical authentication bypass vulnerability in Dromara Sureness security framework versions before 1.0.8. The vulnerability allow...

Oct 25, 2023
CVE-2023-36380
9.8

This vulnerability allows attackers with knowledge of a hard-coded SSH private key to gain unauthorized access to Siemens CP-8031 and CP-8050 MASTER M...

Oct 10, 2023

About CWE-798 (CWE-798)

Our database tracks 444 CVEs classified as CWE-798, with 253 rated critical and 143 rated high severity. The average CVSS score for CWE-798 vulnerabilities is 8.8.

External reference: View CWE-798 on MITRE CWE →

Monitor CWE-798 Vulnerabilities

Get alerted when new CWE-798 CVEs affect your infrastructure.

Start Monitoring Free