CWE-798: CWE-798
Yearly Trend
Top Affected Vendors
All CWE-798 CVEs (451)
CVE-2021-27141 is a critical credential exposure vulnerability affecting FiberHome HG6245D devices. The credentials stored in /fhconf/umconfig.txt are...
Feb 10, 2021FiberHome HG6245D devices contain hardcoded credentials (user/user1234) in their web daemon, allowing attackers to gain administrative access to the d...
Feb 10, 2021This vulnerability involves two undocumented administrator accounts (sftp and mofidev) with hardcoded, non-unique passwords in Mofi Network MOFI4500-4...
Feb 1, 2021This vulnerability allows remote attackers to gain root access to affected Mofi Network routers via SSH using a hard-coded public key stored in read-o...
Feb 1, 2021This vulnerability allows remote attackers to gain full administrative control of Geeni GNC-CW013 smart doorbell devices via Telnet using a default st...
Jan 26, 2021CVE-2020-35929 is a critical vulnerability in TinyCheck where hard-coded credentials in the installation script allow attackers to gain unauthorized a...
Jan 19, 2021This vulnerability allows remote attackers to gain root access to affected Amino Communications set-top boxes via SSH using hard-coded cryptographic k...
Dec 29, 2020Programi Bilanc accounting software versions up to build 007 release 014 install with a hardcoded administrative account (admin/0000) that cannot be c...
Dec 23, 2020This vulnerability involves hardcoded credentials in Programi Bilanc software that allow remote attackers to access multiple servers including website...
Dec 21, 2020CVE-2020-35338 is a critical authentication bypass vulnerability in Mobile Viewpoint WMT Playout Server's web administrative interface. It allows atta...
Dec 14, 2020This CVE exposes a hardcoded administrative password '!j@l#y$z%x6x7q8c9z)' for the TELNET service on affected V-SOL OLT devices. Attackers can use thi...
Nov 29, 2020This vulnerability involves CDATA networking devices having a default hardcoded password 'debug124' for the debug account, allowing attackers to gain ...
Nov 24, 2020This vulnerability affects multiple CDATA optical line terminal (OLT) devices that have a default blank password for the guest account. This allows un...
Nov 24, 2020This vulnerability allows attackers to discover hardcoded administrative credentials in Barco wePresent WiPG-1600W firmware. Attackers can use these c...
Nov 24, 2020Barco wePresent WiPG-1600W devices contain a hardcoded root password hash in their firmware, allowing attackers to gain full system control. This affe...
Nov 24, 2020IBM Spectrum Protect Plus versions 10.1.0 through 10.1.6 contain hard-coded credentials used for authentication and encryption. This allows attackers ...
Nov 23, 2020This CVE involves hard-coded default credentials in PLANET NVR devices that allow root access via telnet. If telnet is exposed to the Internet, attack...
Nov 18, 2020This vulnerability in NATS nats-server allows attackers to bypass authentication by using expired JWT credentials, potentially gaining unauthorized ac...
Nov 6, 2020The Relish VH510 4G hub contains hardcoded admin credentials in firmware versions before 1.0.1.6L0516, allowing remote attackers to gain administrativ...
Nov 4, 2020This vulnerability in NVIDIA DGX servers involves hard-coded credentials in the AMI BMC firmware, allowing attackers to gain elevated privileges or ac...
Oct 29, 2020This CVE describes a critical remote code execution vulnerability in Micro Focus Operation Bridge Manager, Operations Bridge (containerized), and Appl...
Oct 27, 2020CVE-2020-26879 is a critical authentication bypass vulnerability in Ruckus vRioT software where a hardcoded backdoor token allows unauthenticated API ...
Oct 26, 2020This vulnerability allows remote attackers to gain full administrative control of affected Rubetek security cameras via Telnet using a default static ...
Sep 25, 2020CVE-2020-11857 is an authorization bypass vulnerability in Micro Focus Operation Bridge Reporter (OBR) that allows remote attackers to access the OBR ...
Sep 22, 2020This vulnerability allows unauthenticated attackers to gain privileged telnet access to affected D-Link routers using hardcoded credentials. Attackers...
Sep 14, 2020CVE-2020-24876 is a critical vulnerability in Pancake versions before 4.13.29 where a hard-coded cryptographic key allows attackers to forge session c...
Sep 3, 2020IBM Security Verify Access 10.7 contains hard-coded credentials that could allow attackers to bypass authentication, access sensitive data, or comprom...
Aug 4, 2020CVE-2024-27107 is a critical vulnerability in GE HealthCare EchoPAC products where weak default passwords allow attackers to gain unauthorized access....
May 14, 2024This vulnerability involves hardcoded credentials in certain NETGEAR Orbi WiFi systems, allowing attackers to gain administrative access to affected d...
Dec 26, 2021CVE-2021-32454 is a critical vulnerability in SITEL CAP/PRX firmware where hardcoded credentials allow attackers to take over devices. Attackers with ...
May 17, 2021This vulnerability allows attackers to forge valid JWT authentication tokens using a predictable hardcoded secret, enabling complete authentication by...
Oct 15, 2025IBM Security Verify Access Appliance versions 10.0.0 through 10.0.8 contain hard-coded credentials that could allow attackers to authenticate to the s...
Nov 29, 2024CVE-2022-30234 is a critical vulnerability in Schneider Electric Wiser Smart energy management systems where hard-coded credentials allow attackers to...
Jun 2, 2022This vulnerability involves hard-coded clinician passwords in ventilators, allowing attackers to extract credentials and gain unauthorized clinician-l...
Nov 14, 2024This CVE describes a hard-coded credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 devices. Attackers can use these embedded creden...
Jun 25, 2024Nexx Smart Home devices contain hard-coded credentials that allow unauthenticated attackers to access MQTT servers and remotely control garage doors a...
Apr 4, 2023This vulnerability allows attackers to gain administrative control of Meeting Owl devices by using a backdoor password derived from the device's seria...
Jun 2, 2022AquaView versions 1.60, 7.x, and 8.x contain hardcoded credentials that allow authenticated local attackers to manipulate users and system settings. T...
Feb 7, 2022This vulnerability allows attackers to bypass authentication in TIBCO FTL Realm Server due to a hard-coded secret in default configurations. It affect...
Jan 11, 2022This vulnerability allows attackers to extract administrative credentials from Gardyn IoT Hub through API responses, mobile app reverse engineering, o...
Feb 25, 2026This vulnerability allows attackers to access protected administrative areas of the EZCast Pro II web application using well-known default credentials...
Jan 27, 2026This vulnerability allows attackers to bypass authentication in Samsung MagicINFO 9 Server by exploiting hard-coded credentials. It affects all MagicI...
Jul 23, 2025This CVE describes a hardcoded password vulnerability in Forever KidsWatch smartwatches. Attackers can use the embedded default credentials to gain un...
Feb 6, 2025This vulnerability involves hidden maintenance accounts in Sharp and Toshiba multifunction printers/copiers. Attackers who obtain these account passwo...
Nov 26, 2024This vulnerability allows attackers to read default passwords stored in plain text within .sdd files, enabling unauthorized access to SICK industrial ...
Oct 17, 2024CVE-2024-28987 is a hardcoded credential vulnerability in SolarWinds Web Help Desk that allows remote unauthenticated attackers to access internal fun...
Aug 21, 2024This vulnerability allows a high-privileged remote attacker to enable telnet access with hardcoded credentials on affected systems. Attackers can gain...
Jul 9, 2024YourSpotify versions before 1.8.0 use a hardcoded JWT secret, allowing attackers to forge valid authentication tokens for any user. This enables authe...
Mar 13, 2024Multiple MachineSense devices have hardcoded credentials that cannot be changed by users or administrators. This vulnerability allows attackers to gai...
Feb 1, 2024This vulnerability involves hard-coded credentials in FOLIO's mod-data-export-spring module, allowing unauthenticated attackers to access critical API...
Jan 19, 2024About CWE-798 (CWE-798)
Our database tracks 451 CVEs classified as CWE-798, with 258 rated critical and 145 rated high severity. The average CVSS score for CWE-798 vulnerabilities is 8.8.
External reference: View CWE-798 on MITRE CWE →
Monitor CWE-798 Vulnerabilities
Get alerted when new CWE-798 CVEs affect your infrastructure.
Start Monitoring Free