CWE-798: CWE-798

450
Total CVEs
257
Critical
145
High
8.8
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
24
2025
100
2024
97
2023
66
2022
69

Top Affected Vendors

1 Ibm 18
2 Fiberhome 15
3 Dlink 14
4 Totolink 7
5 Siemens 6
6 Schneider Electric 6
7 Solarwinds 5
8 Fortinet 4
9 Tenda 4
10 Dell 4

All CWE-798 CVEs (450)

CVE-2022-24693
9.8

CVE-2022-24693 allows remote attackers to gain SSH access to Baicells Nova436Q and Neutrino 430 cellular base station devices using hardcoded credenti...

Mar 30, 2022
CVE-2022-25521
9.8

CVE-2022-25521 is an access control vulnerability in NUUO network video recorder software that allows attackers to gain unauthorized remote access usi...

Mar 29, 2022
CVE-2022-25246
9.8

This vulnerability allows remote authenticated attackers to take full control of affected systems through hard-coded UltraVNC credentials in Axeda pro...

Mar 16, 2022
CVE-2022-21194
9.8

This vulnerability affects Yokogawa Electric industrial control systems where default Windows account passwords remain unchanged from initial configur...

Mar 11, 2022
CVE-2022-23402
9.8

This vulnerability involves hard-coded credentials in Yokogawa Electric's CENTUM VP and Exaopc products, allowing attackers to gain unauthorized acces...

Mar 11, 2022
CVE-2022-25045
9.8

Home Owners Collection Management System v1.0 contains hardcoded credentials that allow attackers to bypass authentication and access the admin panel....

Mar 2, 2022
CVE-2022-25329
9.8

CVE-2022-25329 is a critical authentication bypass vulnerability in Trend Micro ServerProtect where the Information Server uses static credentials for...

Feb 24, 2022
CVE-2020-36062
9.8

Dairy Farm Shop Management System v1.0 contains hardcoded credentials in its source code, allowing attackers to bypass authentication and gain adminis...

Feb 11, 2022
CVE-2022-22813
9.8

CVE-2022-22813 is a critical vulnerability in Schneider Electric products where hard-coded TLS cryptographic keys allow attackers to decrypt and manip...

Feb 9, 2022
CVE-2020-36064
9.8

Online Course Registration v1.0 contains hardcoded credentials in its source code, allowing attackers to bypass authentication and gain administrative...

Jan 31, 2022
CVE-2022-22928
9.8

CVE-2022-22928 is a critical vulnerability in MCMS v5.2.4 where a hardcoded Shiro key allows attackers to bypass authentication and execute arbitrary ...

Jan 21, 2022
CVE-2022-22845
9.8

CVE-2022-22845 is a critical authentication bypass vulnerability in QXIP SIPCAPTURE homer-app where all installations share the same hardcoded JWT sec...

Jan 10, 2022
CVE-2021-20155
9.8

Trendnet AC2600 TEW-827DRU routers use hardcoded credentials ('12345678') to encrypt configuration backups. This allows attackers to decrypt and poten...

Dec 30, 2021
CVE-2021-43044
9.8

Kaseya Unitrends Backup Appliance versions before 10.5.5 use a weak default SNMP community string, allowing attackers to read and potentially modify S...

Dec 6, 2021
CVE-2021-43136
9.8

CVE-2021-43136 is an authentication bypass vulnerability in FormaLMS learning management systems that allows attackers to gain unauthorized access to ...

Nov 10, 2021
CVE-2021-33583
9.8

REINER timeCard 6.05.07 installs Microsoft SQL Server with a hardcoded sa password in TCServer.jar, allowing attackers to gain full database control. ...

Sep 30, 2021
CVE-2021-41299
9.8

ECOA BAS controllers contain hard-coded credentials in their Linux distribution image, allowing remote attackers to gain administrator privileges with...

Sep 30, 2021
CVE-2020-4690
9.8

IBM Security Guardium 11.3 contains hard-coded credentials that could allow attackers to authenticate to the system, communicate with external compone...

Sep 23, 2021
CVE-2021-21913
9.8

CVE-2021-21913 is a critical vulnerability in D-LINK DIR-3040 routers that allows unauthenticated attackers to execute arbitrary commands via the MQTT...

Sep 23, 2021
CVE-2021-40494
9.8

This vulnerability involves a hardcoded JWT secret key in AdaptiveScale LXDUI that allows attackers to forge authentication tokens and gain administra...

Sep 3, 2021
CVE-2021-34565
9.8

PEPPERL+FUCHS WirelessHART-Gateway devices versions 3.0.7 to 3.0.9 have SSH and telnet services enabled with hard-coded credentials. This allows attac...

Aug 31, 2021
CVE-2021-39613
9.8

This vulnerability involves hard-coded credentials with weak passwords in D-Link DVG-3104MS devices, allowing attackers to gain unauthorized access. I...

Aug 23, 2021
CVE-2021-39615
9.8

CVE-2021-39615 is a critical vulnerability in D-Link DSR-500N routers where hard-coded credentials for undocumented accounts exist in the /etc/passwd ...

Aug 23, 2021
CVE-2013-6276
9.8

This vulnerability involves hardcoded SSH keys in QNAP F_VioCard 2312 and F_VioGate 2308 devices, allowing unauthorized remote access. Only legacy mod...

Aug 9, 2021
CVE-2021-27952
9.8

The ecobee3 lite thermostat version 4.5.81.200 contains hardcoded default root credentials that allow attackers to gain privileged access through the ...

Aug 3, 2021
CVE-2021-37555
9.8

CVE-2021-37555 allows attackers to gain root shell access on TX9 Automatic Food Dispenser devices via telnet using default credentials. This enables c...

Jul 26, 2021
CVE-2021-22707
9.8

This vulnerability involves hard-coded administrative credentials in Schneider Electric EVlink charging stations, allowing attackers to issue unauthor...

Jul 21, 2021
CVE-2020-5349
9.8

Dell EMC Networking S4100 and S5200 Series Switches manufactured before February 2020 contain hardcoded administrative credentials. Remote attackers c...

Jul 19, 2021
CVE-2021-35961
9.8

Dr. ID Door Access Control and Personnel Attendance Management systems have hardcoded default admin credentials, allowing remote attackers to gain ful...

Jul 16, 2021
CVE-2021-21820
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-LINK DIR-3040 routers due to a hard-coded password in the Libcli Test Enviro...

Jul 16, 2021
CVE-2021-33218
9.8

CVE-2021-33218 is a critical vulnerability in CommScope Ruckus IoT Controller where hard-coded system passwords allow attackers to gain shell access. ...

Jul 7, 2021
CVE-2021-32535
9.8

This vulnerability involves hard-coded default credentials in QSAN SANOS storage operating system, allowing unauthenticated remote attackers to gain a...

Jul 7, 2021
CVE-2021-20426
9.8

IBM Security Guardium 11.2 contains hard-coded credentials that could allow attackers to authenticate to the system, communicate with external compone...

May 24, 2021
CVE-2020-21995
9.8

Inim Electronics Smartliving SmartLAN/G/SI devices up to version 6.x use hardcoded default credentials, allowing attackers to gain Telnet, SSH, and FT...

Apr 29, 2021
CVE-2020-35138
9.8

MobileIron MDM agents for Android and iOS contain a hardcoded encryption key used to encrypt authentication credentials. This allows attackers to decr...

Mar 29, 2021
CVE-2021-22667
9.8

This vulnerability affects BB-ESWGP506-2SFP-T industrial switches with hard-coded credentials, allowing attackers to gain unauthorized access and exec...

Feb 24, 2021
CVE-2021-27228
9.8

This vulnerability allows attackers to bypass authentication in Shinobi video surveillance software by exploiting JavaScript prototype pollution. Atta...

Feb 22, 2021
CVE-2021-27159
9.8

FiberHome HG6245D devices contain hardcoded administrative credentials (useradmin/888888) in their web daemon, allowing unauthorized access to the dev...

Feb 10, 2021
CVE-2021-27161
9.8

CVE-2021-27161 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The web management interface c...

Feb 10, 2021
CVE-2021-27163
9.8

CVE-2021-27163 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The devices contain hardcoded ...

Feb 10, 2021
CVE-2021-27165
9.8

CVE-2021-27165 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. Attackers can exploit hardcode...

Feb 10, 2021
CVE-2021-27167
9.8

CVE-2021-27167 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The admin account has a hardco...

Feb 10, 2021
CVE-2021-27169
9.8

CVE-2021-27169 is a critical vulnerability affecting FiberHome AN5506-04-FA optical network terminals with firmware RP2631. It involves hardcoded cred...

Feb 10, 2021
CVE-2021-27147
9.8

FiberHome HG6245D devices contain hardcoded admin/admin credentials in their web daemon, allowing attackers to gain administrative access to the devic...

Feb 10, 2021
CVE-2021-27149
9.8

CVE-2021-27149 is a critical authentication bypass vulnerability affecting FiberHome HG6245D devices. Attackers can use hardcoded admin credentials (a...

Feb 10, 2021
CVE-2021-27151
9.8

FiberHome HG6245D optical network terminal devices contain hardcoded root credentials (rootmet/m3tr0r00t) in their web daemon. This allows attackers t...

Feb 10, 2021
CVE-2021-27153
9.8

CVE-2021-27153 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The web daemon contains hardco...

Feb 10, 2021
CVE-2021-27155
9.8

CVE-2021-27155 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The web daemon contains hardco...

Feb 10, 2021
CVE-2021-27157
9.8

CVE-2021-27157 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The web daemon contains hardco...

Feb 10, 2021
CVE-2021-27145
9.8

FiberHome HG6245D devices contain hardcoded admin credentials (admin/lnadmin) in the web daemon, allowing attackers to gain administrative access. Thi...

Feb 10, 2021

About CWE-798 (CWE-798)

Our database tracks 450 CVEs classified as CWE-798, with 257 rated critical and 145 rated high severity. The average CVSS score for CWE-798 vulnerabilities is 8.8.

External reference: View CWE-798 on MITRE CWE →

Monitor CWE-798 Vulnerabilities

Get alerted when new CWE-798 CVEs affect your infrastructure.

Start Monitoring Free