CWE-798: CWE-798

448
Total CVEs
256
Critical
144
High
8.8
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
24
2025
100
2024
97
2023
66
2022
69

Top Affected Vendors

1 Ibm 18
2 Fiberhome 15
3 Dlink 14
4 Totolink 7
5 Schneider Electric 6
6 Siemens 6
7 Solarwinds 5
8 Fortinet 4
9 Tenda 4
10 Dell 4

All CWE-798 CVEs (448)

CVE-2023-20101
9.8

This vulnerability allows unauthenticated remote attackers to log into Cisco Emergency Responder systems using static root credentials that cannot be ...

Oct 4, 2023
CVE-2023-5074
9.8

CVE-2023-5074 is a critical authentication bypass vulnerability in D-Link D-View 8 network management software. Attackers can forge valid JWT authenti...

Sep 20, 2023
CVE-2023-42336
9.8

This critical vulnerability in NETIS SYSTEMS WF2409Ev4 routers allows remote attackers to execute arbitrary code and access sensitive information thro...

Sep 16, 2023
CVE-2023-37755
9.8

i-doit pro and open versions 25 and below have hardcoded default administrator credentials with no forced password change. Unauthenticated attackers c...

Sep 14, 2023
CVE-2023-41508
9.8

CVE-2023-41508 is a hard-coded credential vulnerability in Super Store Finder v3.6 that allows attackers to bypass authentication and gain administrat...

Sep 5, 2023
CVE-2023-38026
9.8

This vulnerability allows remote attackers to access SpotCam FHD 2 devices using hard-coded uBoot credentials. Attackers can perform arbitrary system ...

Aug 28, 2023
CVE-2023-38024
9.8

This vulnerability allows remote attackers to access SpotCam FHD 2 devices via hidden Telnet using hard-coded credentials. Attackers can execute arbit...

Aug 28, 2023
CVE-2023-33372
9.8

Connected IO devices v2.1.0 and earlier contain hard-coded MQTT credentials in firmware, allowing attackers to connect to the MQTT broker and imperson...

Aug 4, 2023
CVE-2023-33371
9.8

This vulnerability allows attackers to forge valid JWT session tokens using a hardcoded cryptographic key, enabling authentication bypass in Control I...

Aug 3, 2023
CVE-2023-32227
9.8

Synel SYnergy Fingerprint Terminals contain hard-coded credentials that allow attackers to gain unauthorized access. This affects all organizations us...

Jul 30, 2023
CVE-2023-37286
9.8

SmartSoft SmartBPM.NET uses a hard-coded machine key that allows unauthenticated remote attackers to send serialized payloads to execute arbitrary cod...

Jul 10, 2023
CVE-2023-35987
9.8

PiiGAB M-Bus devices contain hard-coded credentials that allow authentication bypass. This affects all systems using vulnerable PiiGAB M-Bus products,...

Jul 6, 2023
CVE-2022-4333
9.8

CVE-2022-4333 involves hardcoded credentials in multiple SPRECON-E CPU variants from Sprecher Automation, allowing remote attackers to take over affec...

Jun 1, 2023
CVE-2023-33778
9.8

Draytek Vigor routers, access points, switches, and Myvigor firmware use hardcoded encryption keys, allowing attackers to bind affected devices to the...

Jun 1, 2023
CVE-2023-33236
9.8

MXsecurity version 1.0 contains hardcoded credentials that allow attackers to craft arbitrary JWT tokens and bypass authentication for web-based APIs....

May 22, 2023
CVE-2023-30352
9.8

This vulnerability allows attackers to access the RTSP video feed of Tenda CP3 IP cameras using a hard-coded default password. Anyone using the affect...

May 10, 2023
CVE-2023-26089
9.8

CVE-2023-26089 allows authentication bypass in European Chemicals Agency IUCLID 6.x software due to a weak hard-coded secret used for JWT signing. Att...

May 2, 2023
CVE-2022-41397
9.8

Sage 300's optional Web Screens and Global Search features use a hard-coded encryption key ('LandlordPassKey') to protect sensitive data in configurat...

Apr 28, 2023
CVE-2022-41400
9.8

Sage 300 uses a hard-coded encryption key to protect sensitive data like passwords and SQL connection strings. Attackers who gain access to the encryp...

Apr 28, 2023
CVE-2022-39989
9.8

Fighting Cock Information System 1.0 uses hardcoded default credentials that administrators cannot change during installation. This allows attackers t...

Apr 26, 2023
CVE-2023-24501
9.8

Electra Central AC units contain hardcoded credentials in unspecified code, allowing attackers to gain unauthorized access to the system. This affects...

Apr 17, 2023
CVE-2023-28654
9.8

Osprey Pump Controller version 1.01 contains a hidden administrative account with a hardcoded password that cannot be changed, allowing full access to...

Mar 28, 2023
CVE-2022-22512
9.8

CVE-2022-22512 involves hard-coded administrative credentials in the web interface of multiple VARTA Storage products, allowing unauthorized attackers...

Mar 23, 2023
CVE-2023-26511
9.8

CVE-2023-26511 is a critical authentication bypass vulnerability in Propius MachineSelector's web admin panel. Attackers can exploit hard-coded admin ...

Mar 14, 2023
CVE-2023-1269
9.8

CVE-2023-1269 involves hard-coded credentials in the easyappointments scheduling software, allowing attackers to gain unauthorized access to the appli...

Mar 8, 2023
CVE-2021-36224
9.8

This vulnerability allows unauthenticated attackers to gain root access to Western Digital My Cloud network-attached storage devices by exploiting a d...

Feb 6, 2023
CVE-2022-48113
9.8

This vulnerability allows unauthenticated attackers to access the telnet service on TOTOLINK N200RE_v5 routers via a crafted POST request, then gain r...

Feb 2, 2023
CVE-2022-3214
9.8

Delta Industrial Automation's DIAEnergy system contains hard-coded credentials that allow attackers to upload executable files to specific directories...

Sep 16, 2022
CVE-2022-30274
9.8

CVE-2022-30274 is a critical vulnerability in Motorola ACE1000 RTU devices where credentials and authentication data are encrypted using the Tiny Encr...

Jul 26, 2022
CVE-2022-29953
9.8

CVE-2022-29953 exposes Bently Nevada 3700 series condition monitoring equipment through hardcoded credentials on a maintenance interface. Attackers co...

Jul 26, 2022
CVE-2022-34907
9.8

An authentication bypass vulnerability in FileWave allows unauthenticated attackers to gain administrative access to the platform. This affects FileWa...

Jul 25, 2022
CVE-2022-26138
9.8

The Atlassian Questions For Confluence app creates a default user account with a hardcoded password, allowing remote unauthenticated attackers to log ...

Jul 20, 2022
CVE-2022-34045
9.8

This vulnerability involves a hardcoded encryption key in Wavlink routers that allows attackers to decrypt configuration files and potentially gain ad...

Jul 20, 2022
CVE-2022-2107
9.8

The MiCODUS MV720 GPS tracker API server uses a hard-coded master password in its authentication mechanism, allowing attackers to send SMS commands to...

Jul 20, 2022
CVE-2022-24657
9.8

Goldshell ASIC Miners v2.1.x contain hardcoded SSH credentials that allow attackers to remotely connect to the devices. This affects all Goldshell ASI...

Jul 20, 2022
CVE-2022-32985
9.8

CVE-2022-32985 is a critical vulnerability in Nexans FTTO GigaSwitch devices that implements a hardcoded backdoor account for SSH access on ports 5020...

Jul 17, 2022
CVE-2022-35857
9.8

CVE-2022-35857 is a critical remote code execution vulnerability in kvf-admin that allows attackers to execute arbitrary code on affected systems. The...

Jul 13, 2022
CVE-2020-4150
9.8

IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials that can be used for authentication, communication, or data encryption. This allows ...

Jul 11, 2022
CVE-2021-40597
9.8

This vulnerability allows attackers to gain administrative access to EDIMAX IC-3140W IP cameras using hardcoded credentials. Anyone using the affected...

Jun 29, 2022
CVE-2022-34005
9.8

TitanFTP NextGen versions before 1.2.1050 have a hardcoded password for the SQL Server 'sa' account, allowing attackers to gain administrative databas...

Jun 19, 2022
CVE-2022-30422
9.8

CVE-2022-30422 allows remote attackers to execute arbitrary code on Planet Time Enterprise servers by manipulating the Viewstate parameter. This affec...

Jun 17, 2022
CVE-2021-40903
9.8

CVE-2021-40903 is an authentication bypass vulnerability in Antminer Monitor 0.50.0 due to a static secret string in Flask server settings instead of ...

Jun 17, 2022
CVE-2022-29525
9.8

CVE-2022-29525 is a critical authentication bypass vulnerability in Rakuten Casa devices where hard-coded root credentials allow remote attackers to g...

Jun 13, 2022
CVE-2022-29730
9.8

USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 contains hard-coded administrative credentials that cannot be changed through normal device oper...

Jun 2, 2022
CVE-2022-28605
9.8

CVE-2022-28605 is a critical authentication bypass vulnerability in SoundBar apps using Linkplay SDK 1.00 where a hardcoded admin token allows remote ...

Jun 2, 2022
CVE-2021-33016
9.8

CVE-2021-33016 allows attackers to gain full read/write/delete access to sensitive folders on KUKA KR C4 industrial control systems due to hard-coded ...

May 26, 2022
CVE-2022-29644
9.8

This vulnerability involves a hard-coded password for the telnet service in TOTOLINK A3100R routers, allowing attackers to gain unauthorized administr...

May 18, 2022
CVE-2021-38969
9.8

This vulnerability in IBM Spectrum Virtualize allows attackers to gain unauthorized access by reusing support-generated credentials. It affects IBM Sp...

May 11, 2022
CVE-2022-25569
9.8

Bettini Srl GAMS Product Line v4.3.0 uses the same static SSH private key across all installations, allowing attackers to extract the key from the sof...

Apr 4, 2022
CVE-2021-30064
9.8

This vulnerability allows attackers to gain SSH access to Schneider Electric ConneXium Tofino Firewall and Belden Tofino Xenon Security Appliance devi...

Apr 3, 2022

About CWE-798 (CWE-798)

Our database tracks 448 CVEs classified as CWE-798, with 256 rated critical and 144 rated high severity. The average CVSS score for CWE-798 vulnerabilities is 8.8.

External reference: View CWE-798 on MITRE CWE →

Monitor CWE-798 Vulnerabilities

Get alerted when new CWE-798 CVEs affect your infrastructure.

Start Monitoring Free