CWE-798: CWE-798

451
Total CVEs
258
Critical
145
High
8.8
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
24
2025
100
2024
97
2023
66
2022
69

Top Affected Vendors

1 Ibm 19
2 Fiberhome 15
3 Dlink 14
4 Totolink 7
5 Siemens 6
6 Schneider Electric 6
7 Solarwinds 5
8 Fortinet 4
9 Tenda 4
10 Dell 4

All CWE-798 CVEs (451)

CVE-2021-27141
9.8

CVE-2021-27141 is a critical credential exposure vulnerability affecting FiberHome HG6245D devices. The credentials stored in /fhconf/umconfig.txt are...

Feb 10, 2021
CVE-2021-27143
9.8

FiberHome HG6245D devices contain hardcoded credentials (user/user1234) in their web daemon, allowing attackers to gain administrative access to the d...

Feb 10, 2021
CVE-2020-13858
9.8

This vulnerability involves two undocumented administrator accounts (sftp and mofidev) with hardcoded, non-unique passwords in Mofi Network MOFI4500-4...

Feb 1, 2021
CVE-2020-15833
9.8

This vulnerability allows remote attackers to gain root access to affected Mofi Network routers via SSH using a hard-coded public key stored in read-o...

Feb 1, 2021
CVE-2020-28998
9.8

This vulnerability allows remote attackers to gain full administrative control of Geeni GNC-CW013 smart doorbell devices via Telnet using a default st...

Jan 26, 2021
CVE-2020-35929
9.8

CVE-2020-35929 is a critical vulnerability in TinyCheck where hard-coded credentials in the installation script allow attackers to gain unauthorized a...

Jan 19, 2021
CVE-2020-10210
9.8

This vulnerability allows remote attackers to gain root access to affected Amino Communications set-top boxes via SSH using hard-coded cryptographic k...

Dec 29, 2020
CVE-2020-11720
9.8

Programi Bilanc accounting software versions up to build 007 release 014 install with a hardcoded administrative account (admin/0000) that cannot be c...

Dec 23, 2020
CVE-2020-8995
9.8

This vulnerability involves hardcoded credentials in Programi Bilanc software that allow remote attackers to access multiple servers including website...

Dec 21, 2020
CVE-2020-35338
9.8

CVE-2020-35338 is a critical authentication bypass vulnerability in Mobile Viewpoint WMT Playout Server's web administrative interface. It allows atta...

Dec 14, 2020
CVE-2020-29376
9.8

This CVE exposes a hardcoded administrative password '!j@l#y$z%x6x7q8c9z)' for the TELNET service on affected V-SOL OLT devices. Attackers can use thi...

Nov 29, 2020
CVE-2020-29060
9.8

This vulnerability involves CDATA networking devices having a default hardcoded password 'debug124' for the debug account, allowing attackers to gain ...

Nov 24, 2020
CVE-2020-29062
9.8

This vulnerability affects multiple CDATA optical line terminal (OLT) devices that have a default blank password for the guest account. This allows un...

Nov 24, 2020
CVE-2020-28329
9.8

This vulnerability allows attackers to discover hardcoded administrative credentials in Barco wePresent WiPG-1600W firmware. Attackers can use these c...

Nov 24, 2020
CVE-2020-28334
9.8

Barco wePresent WiPG-1600W devices contain a hardcoded root password hash in their firmware, allowing attackers to gain full system control. This affe...

Nov 24, 2020
CVE-2020-4854
9.8

IBM Spectrum Protect Plus versions 10.1.0 through 10.1.6 contain hard-coded credentials used for authentication and encryption. This allows attackers ...

Nov 23, 2020
CVE-2020-26097
9.8

This CVE involves hard-coded default credentials in PLANET NVR devices that allow root access via telnet. If telnet is exposed to the Internet, attack...

Nov 18, 2020
CVE-2020-26892
9.8

This vulnerability in NATS nats-server allows attackers to bypass authentication by using expired JWT credentials, potentially gaining unauthorized ac...

Nov 6, 2020
CVE-2020-27689
9.8

The Relish VH510 4G hub contains hardcoded admin credentials in firmware versions before 1.0.1.6L0516, allowing remote attackers to gain administrativ...

Nov 4, 2020
CVE-2020-11483
9.8

This vulnerability in NVIDIA DGX servers involves hard-coded credentials in the AMI BMC firmware, allowing attackers to gain elevated privileges or ac...

Oct 29, 2020
CVE-2020-11854
9.8

This CVE describes a critical remote code execution vulnerability in Micro Focus Operation Bridge Manager, Operations Bridge (containerized), and Appl...

Oct 27, 2020
CVE-2020-26879
9.8

CVE-2020-26879 is a critical authentication bypass vulnerability in Ruckus vRioT software where a hardcoded backdoor token allows unauthenticated API ...

Oct 26, 2020
CVE-2020-25749
9.8

This vulnerability allows remote attackers to gain full administrative control of affected Rubetek security cameras via Telnet using a default static ...

Sep 25, 2020
CVE-2020-11857
9.8

CVE-2020-11857 is an authorization bypass vulnerability in Micro Focus Operation Bridge Reporter (OBR) that allows remote attackers to access the OBR ...

Sep 22, 2020
CVE-2018-20432
9.8

This vulnerability allows unauthenticated attackers to gain privileged telnet access to affected D-Link routers using hardcoded credentials. Attackers...

Sep 14, 2020
CVE-2020-24876
9.8

CVE-2020-24876 is a critical vulnerability in Pancake versions before 4.13.29 where a hard-coded cryptographic key allows attackers to forge session c...

Sep 3, 2020
CVE-2020-4459
9.8

IBM Security Verify Access 10.7 contains hard-coded credentials that could allow attackers to bypass authentication, access sensitive data, or comprom...

Aug 4, 2020
CVE-2024-27107
9.6

CVE-2024-27107 is a critical vulnerability in GE HealthCare EchoPAC products where weak default passwords allow attackers to gain unauthorized access....

May 14, 2024
CVE-2021-45520
9.6

This vulnerability involves hardcoded credentials in certain NETGEAR Orbi WiFi systems, allowing attackers to gain administrative access to affected d...

Dec 26, 2021
CVE-2021-32454
9.6

CVE-2021-32454 is a critical vulnerability in SITEL CAP/PRX firmware where hardcoded credentials allow attackers to take over devices. Attackers with ...

May 17, 2021
CVE-2025-56749
9.4

This vulnerability allows attackers to forge valid JWT authentication tokens using a predictable hardcoded secret, enabling complete authentication by...

Oct 15, 2025
CVE-2024-49805
9.4

IBM Security Verify Access Appliance versions 10.0.0 through 10.0.8 contain hard-coded credentials that could allow attackers to authenticate to the s...

Nov 29, 2024
CVE-2022-30234
9.4

CVE-2022-30234 is a critical vulnerability in Schneider Electric Wiser Smart energy management systems where hard-coded credentials allow attackers to...

Jun 2, 2022
CVE-2024-48971
9.3

This vulnerability involves hard-coded clinician passwords in ventilators, allowing attackers to extract credentials and gain unauthorized clinician-l...

Nov 14, 2024
CVE-2023-6198
9.3

This CVE describes a hard-coded credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 devices. Attackers can use these embedded creden...

Jun 25, 2024
CVE-2023-1748
9.3

Nexx Smart Home devices contain hard-coded credentials that allow unauthenticated attackers to access MQTT servers and remotely control garage doors a...

Apr 4, 2023
CVE-2022-31462
9.3

This vulnerability allows attackers to gain administrative control of Meeting Owl devices by using a backdoor password derived from the device's seria...

Jun 2, 2022
CVE-2021-42833
9.3

AquaView versions 1.60, 7.x, and 8.x contain hardcoded credentials that allow authenticated local attackers to manipulate users and system settings. T...

Feb 7, 2022
CVE-2021-43052
9.3

This vulnerability allows attackers to bypass authentication in TIBCO FTL Realm Server due to a hard-coded secret in default configurations. It affect...

Jan 11, 2022
CVE-2025-1242
9.1

This vulnerability allows attackers to extract administrative credentials from Gardyn IoT Hub through API responses, mobile app reverse engineering, o...

Feb 25, 2026
CVE-2026-24346
9.1

This vulnerability allows attackers to access protected administrative areas of the EZCast Pro II web application using well-known default credentials...

Jan 27, 2026
CVE-2025-54454
9.1

This vulnerability allows attackers to bypass authentication in Samsung MagicINFO 9 Server by exploiting hard-coded credentials. It affects all MagicI...

Jul 23, 2025
CVE-2024-36556
9.1

This CVE describes a hardcoded password vulnerability in Forever KidsWatch smartwatches. Attackers can use the embedded default credentials to gain un...

Feb 6, 2025
CVE-2024-35244
9.1

This vulnerability involves hidden maintenance accounts in Sharp and Toshiba multifunction printers/copiers. Attackers who obtain these account passwo...

Nov 26, 2024
CVE-2024-10025
9.1

This vulnerability allows attackers to read default passwords stored in plain text within .sdd files, enabling unauthorized access to SICK industrial ...

Oct 17, 2024
CVE-2024-28987
9.1

CVE-2024-28987 is a hardcoded credential vulnerability in SolarWinds Web Help Desk that allows remote unauthenticated attackers to access internal fun...

Aug 21, 2024
CVE-2024-28751
9.1

This vulnerability allows a high-privileged remote attacker to enable telnet access with hardcoded credentials on affected systems. Attackers can gain...

Jul 9, 2024
CVE-2024-28194
9.1

YourSpotify versions before 1.8.0 use a hardcoded JWT secret, allowing attackers to forge valid authentication tokens for any user. This enables authe...

Mar 13, 2024
CVE-2023-46706
9.1

Multiple MachineSense devices have hardcoded credentials that cannot be changed by users or administrators. This vulnerability allows attackers to gai...

Feb 1, 2024
CVE-2024-23687
9.1

This vulnerability involves hard-coded credentials in FOLIO's mod-data-export-spring module, allowing unauthenticated attackers to access critical API...

Jan 19, 2024

About CWE-798 (CWE-798)

Our database tracks 451 CVEs classified as CWE-798, with 258 rated critical and 145 rated high severity. The average CVSS score for CWE-798 vulnerabilities is 8.8.

External reference: View CWE-798 on MITRE CWE →

Monitor CWE-798 Vulnerabilities

Get alerted when new CWE-798 CVEs affect your infrastructure.

Start Monitoring Free