CWE-798: CWE-798
Yearly Trend
Top Affected Vendors
All CWE-798 CVEs (450)
CVE-2022-24693 allows remote attackers to gain SSH access to Baicells Nova436Q and Neutrino 430 cellular base station devices using hardcoded credenti...
Mar 30, 2022CVE-2022-25521 is an access control vulnerability in NUUO network video recorder software that allows attackers to gain unauthorized remote access usi...
Mar 29, 2022This vulnerability allows remote authenticated attackers to take full control of affected systems through hard-coded UltraVNC credentials in Axeda pro...
Mar 16, 2022This vulnerability affects Yokogawa Electric industrial control systems where default Windows account passwords remain unchanged from initial configur...
Mar 11, 2022This vulnerability involves hard-coded credentials in Yokogawa Electric's CENTUM VP and Exaopc products, allowing attackers to gain unauthorized acces...
Mar 11, 2022Home Owners Collection Management System v1.0 contains hardcoded credentials that allow attackers to bypass authentication and access the admin panel....
Mar 2, 2022CVE-2022-25329 is a critical authentication bypass vulnerability in Trend Micro ServerProtect where the Information Server uses static credentials for...
Feb 24, 2022Dairy Farm Shop Management System v1.0 contains hardcoded credentials in its source code, allowing attackers to bypass authentication and gain adminis...
Feb 11, 2022CVE-2022-22813 is a critical vulnerability in Schneider Electric products where hard-coded TLS cryptographic keys allow attackers to decrypt and manip...
Feb 9, 2022Online Course Registration v1.0 contains hardcoded credentials in its source code, allowing attackers to bypass authentication and gain administrative...
Jan 31, 2022CVE-2022-22928 is a critical vulnerability in MCMS v5.2.4 where a hardcoded Shiro key allows attackers to bypass authentication and execute arbitrary ...
Jan 21, 2022CVE-2022-22845 is a critical authentication bypass vulnerability in QXIP SIPCAPTURE homer-app where all installations share the same hardcoded JWT sec...
Jan 10, 2022Trendnet AC2600 TEW-827DRU routers use hardcoded credentials ('12345678') to encrypt configuration backups. This allows attackers to decrypt and poten...
Dec 30, 2021Kaseya Unitrends Backup Appliance versions before 10.5.5 use a weak default SNMP community string, allowing attackers to read and potentially modify S...
Dec 6, 2021CVE-2021-43136 is an authentication bypass vulnerability in FormaLMS learning management systems that allows attackers to gain unauthorized access to ...
Nov 10, 2021REINER timeCard 6.05.07 installs Microsoft SQL Server with a hardcoded sa password in TCServer.jar, allowing attackers to gain full database control. ...
Sep 30, 2021ECOA BAS controllers contain hard-coded credentials in their Linux distribution image, allowing remote attackers to gain administrator privileges with...
Sep 30, 2021IBM Security Guardium 11.3 contains hard-coded credentials that could allow attackers to authenticate to the system, communicate with external compone...
Sep 23, 2021CVE-2021-21913 is a critical vulnerability in D-LINK DIR-3040 routers that allows unauthenticated attackers to execute arbitrary commands via the MQTT...
Sep 23, 2021This vulnerability involves a hardcoded JWT secret key in AdaptiveScale LXDUI that allows attackers to forge authentication tokens and gain administra...
Sep 3, 2021PEPPERL+FUCHS WirelessHART-Gateway devices versions 3.0.7 to 3.0.9 have SSH and telnet services enabled with hard-coded credentials. This allows attac...
Aug 31, 2021This vulnerability involves hard-coded credentials with weak passwords in D-Link DVG-3104MS devices, allowing attackers to gain unauthorized access. I...
Aug 23, 2021CVE-2021-39615 is a critical vulnerability in D-Link DSR-500N routers where hard-coded credentials for undocumented accounts exist in the /etc/passwd ...
Aug 23, 2021This vulnerability involves hardcoded SSH keys in QNAP F_VioCard 2312 and F_VioGate 2308 devices, allowing unauthorized remote access. Only legacy mod...
Aug 9, 2021The ecobee3 lite thermostat version 4.5.81.200 contains hardcoded default root credentials that allow attackers to gain privileged access through the ...
Aug 3, 2021CVE-2021-37555 allows attackers to gain root shell access on TX9 Automatic Food Dispenser devices via telnet using default credentials. This enables c...
Jul 26, 2021This vulnerability involves hard-coded administrative credentials in Schneider Electric EVlink charging stations, allowing attackers to issue unauthor...
Jul 21, 2021Dell EMC Networking S4100 and S5200 Series Switches manufactured before February 2020 contain hardcoded administrative credentials. Remote attackers c...
Jul 19, 2021Dr. ID Door Access Control and Personnel Attendance Management systems have hardcoded default admin credentials, allowing remote attackers to gain ful...
Jul 16, 2021This vulnerability allows remote attackers to execute arbitrary code on D-LINK DIR-3040 routers due to a hard-coded password in the Libcli Test Enviro...
Jul 16, 2021CVE-2021-33218 is a critical vulnerability in CommScope Ruckus IoT Controller where hard-coded system passwords allow attackers to gain shell access. ...
Jul 7, 2021This vulnerability involves hard-coded default credentials in QSAN SANOS storage operating system, allowing unauthenticated remote attackers to gain a...
Jul 7, 2021IBM Security Guardium 11.2 contains hard-coded credentials that could allow attackers to authenticate to the system, communicate with external compone...
May 24, 2021Inim Electronics Smartliving SmartLAN/G/SI devices up to version 6.x use hardcoded default credentials, allowing attackers to gain Telnet, SSH, and FT...
Apr 29, 2021MobileIron MDM agents for Android and iOS contain a hardcoded encryption key used to encrypt authentication credentials. This allows attackers to decr...
Mar 29, 2021This vulnerability affects BB-ESWGP506-2SFP-T industrial switches with hard-coded credentials, allowing attackers to gain unauthorized access and exec...
Feb 24, 2021This vulnerability allows attackers to bypass authentication in Shinobi video surveillance software by exploiting JavaScript prototype pollution. Atta...
Feb 22, 2021FiberHome HG6245D devices contain hardcoded administrative credentials (useradmin/888888) in their web daemon, allowing unauthorized access to the dev...
Feb 10, 2021CVE-2021-27161 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The web management interface c...
Feb 10, 2021CVE-2021-27163 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The devices contain hardcoded ...
Feb 10, 2021CVE-2021-27165 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. Attackers can exploit hardcode...
Feb 10, 2021CVE-2021-27167 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The admin account has a hardco...
Feb 10, 2021CVE-2021-27169 is a critical vulnerability affecting FiberHome AN5506-04-FA optical network terminals with firmware RP2631. It involves hardcoded cred...
Feb 10, 2021FiberHome HG6245D devices contain hardcoded admin/admin credentials in their web daemon, allowing attackers to gain administrative access to the devic...
Feb 10, 2021CVE-2021-27149 is a critical authentication bypass vulnerability affecting FiberHome HG6245D devices. Attackers can use hardcoded admin credentials (a...
Feb 10, 2021FiberHome HG6245D optical network terminal devices contain hardcoded root credentials (rootmet/m3tr0r00t) in their web daemon. This allows attackers t...
Feb 10, 2021CVE-2021-27153 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The web daemon contains hardco...
Feb 10, 2021CVE-2021-27155 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The web daemon contains hardco...
Feb 10, 2021CVE-2021-27157 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The web daemon contains hardco...
Feb 10, 2021FiberHome HG6245D devices contain hardcoded admin credentials (admin/lnadmin) in the web daemon, allowing attackers to gain administrative access. Thi...
Feb 10, 2021About CWE-798 (CWE-798)
Our database tracks 450 CVEs classified as CWE-798, with 257 rated critical and 145 rated high severity. The average CVSS score for CWE-798 vulnerabilities is 8.8.
External reference: View CWE-798 on MITRE CWE →
Monitor CWE-798 Vulnerabilities
Get alerted when new CWE-798 CVEs affect your infrastructure.
Start Monitoring Free