CWE-798: CWE-798

455
Total CVEs
261
Critical
146
High
8.8
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
24
2025
100
2024
97
2023
66
2022
69

Top Affected Vendors

1 Ibm 20
2 Fiberhome 15
3 Dlink 14
4 Totolink 7
5 Siemens 6
6 Schneider Electric 6
7 Cisco 5
8 Solarwinds 5
9 Fortinet 4
10 Tenda 4

All CWE-798 CVEs (455)

CVE-2023-2504
8.4

This CVE describes a vulnerability in Birddog firmware where hard-coded credentials are present in files on firmware images. An attacker can use these...

May 22, 2023
CVE-2021-27430
8.4

This vulnerability in GE UR bootloader versions 7.00-7.02 contains hardcoded credentials that could allow unauthorized access. Attackers with physical...

Mar 23, 2022
CVE-2024-9334
8.2

This vulnerability in E-Kent Pallium Vehicle Tracking software allows attackers to bypass authentication using hard-coded credentials stored without p...

Feb 27, 2025
CVE-2021-31579
8.2

Akkadian Provisioning Manager Engine ships with a hard-coded credential (akkadianuser:haakkadianpassword) that allows unauthorized access. This affect...

Jul 22, 2021
CVE-2025-40938
8.1

This vulnerability in SIMATIC CN 4100 devices involves sensitive information being stored in firmware, allowing attackers to extract and misuse this d...

Dec 9, 2025
CVE-2024-28875
8.1

The LevelOne WBR-6012 router contains a hard-coded backdoor credential '@m!t2K1' that grants admin access during the first 30 seconds after boot. Atta...

Oct 30, 2024
CVE-2024-5460
8.1

A vulnerability in Brocade Fabric OS allows authenticated remote attackers to read device data via SNMP using hard-coded default community strings. Th...

Jun 26, 2024
CVE-2023-48251
8.1

This vulnerability allows remote attackers to authenticate to SSH services with root privileges using a hidden hard-coded account. It affects Bosch Re...

Jan 10, 2024
CVE-2023-48250
8.1

This vulnerability allows remote attackers to authenticate to affected Bosch web applications using hidden hard-coded accounts with high privileges. A...

Jan 10, 2024
CVE-2023-43870
8.1

CVE-2023-43870 allows attackers to extract the root certificate password from Net2 software installation files, enabling them to create fraudulent cer...

Dec 19, 2023
CVE-2022-29060
8.1

This vulnerability involves hard-coded cryptographic keys in FortiDDoS API versions 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2...

Jul 19, 2022
CVE-2021-32993
8.1

This vulnerability involves hard-coded credentials in IntelliBridge EC 40 and 60 Hub devices, allowing attackers to gain unauthorized access to the sy...

Dec 27, 2021
CVE-2021-44207
8.1

CVE-2021-44207 is a vulnerability in Acclaim USAHERDS software where hard-coded credentials allow attackers to gain unauthorized access. This affects ...

Dec 21, 2021
CVE-2021-26611
8.1

CVE-2021-26611 is a hard-coded credentials vulnerability in HejHome GKW-IC052 IP cameras that allows remote attackers to gain administrative control. ...

Nov 26, 2021
CVE-2026-24840
8.0

Dokploy versions before 0.26.6 contain hardcoded database credentials in the installation script, allowing attackers with network access to the databa...

Jan 28, 2026
CVE-2025-27255
8.0

GE Vernova EnerVista UR Setup software contains hard-coded credentials that encrypt the local user database. Attackers who analyze the application cod...

Mar 10, 2025
CVE-2024-52788
8.0

Tenda W9 routers version 1.0.0.7(4456) contain a hardcoded root password in the /etc_ro/shadow file, allowing attackers to gain administrative access....

Nov 19, 2024
CVE-2024-48192
8.0

This vulnerability allows attackers to gain root access to Tenda G3 routers using a hardcoded password stored in the /etc_ro/shadow file. Anyone using...

Oct 17, 2024
CVE-2022-22765
8.0

CVE-2022-22765 is a hardcoded credentials vulnerability in BD Viper LT medical laboratory automation systems. Exploitation allows attackers to access,...

Feb 12, 2022
CVE-2026-26334
7.8

Calero VeraSMART versions before 2026 R1 contain hardcoded AES encryption keys in the Veramark.Framework.dll file. This allows attackers with local sy...

Feb 13, 2026
CVE-2024-0865
7.8

This vulnerability involves hard-coded credentials in Schneider Electric software that allow local privilege escalation. Non-administrative users can ...

Jun 12, 2024
CVE-2023-49221
7.8

This vulnerability allows attackers on the same local network to bypass security restrictions on Precor fitness equipment touchscreen consoles using a...

Jun 7, 2024
CVE-2023-51588
7.8

This vulnerability allows local attackers with initial low-privileged access to escalate to SYSTEM privileges on Voltronic Power ViewPower Pro install...

May 3, 2024
CVE-2023-36623
7.8

This vulnerability allows local attackers to calculate the root password of Loxone Miniserver Go Gen.2 devices using hard-coded secrets and the device...

Jul 5, 2023
CVE-2023-2291
7.8

This vulnerability involves hardcoded static credentials in PostgreSQL data used by ManageEngine Access Manager Plus, Password Manager Pro, and PAM360...

Apr 26, 2023
CVE-2023-22429
7.8

The Wolt Delivery Android app versions 4.27.2 and earlier contain hard-coded API credentials that can be extracted through reverse engineering. This a...

Apr 11, 2023
CVE-2022-25217
7.8

This vulnerability allows attackers on the local network to gain root access to affected devices via telnet by exploiting hard-coded cryptographic key...

Mar 10, 2022
CVE-2021-33220
7.8

CommScope Ruckus IoT Controller versions 1.7.1.0 and earlier contain hard-coded API keys that cannot be changed. This allows attackers to bypass authe...

Jul 7, 2021
CVE-2020-4932
7.8

IBM QRadar SIEM versions 7.3 and 7.4 contain hard-coded credentials that could allow attackers to authenticate to the system, communicate with externa...

May 5, 2021
CVE-2021-20401
7.8

IBM QRadar SIEM versions 7.3 and 7.4 contain hard-coded credentials that could allow attackers to authenticate to the system, communicate with externa...

May 5, 2021
CVE-2020-35567
7.8

This vulnerability involves MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software using a hardcoded database password shared across all installations...

Feb 16, 2021
CVE-2019-20471
7.8

The TK-Star Q90 Junior GPS smartwatch uses a hardcoded default administrative password (123456) that cannot be changed during initial setup. This allo...

Feb 1, 2021
CVE-2021-1219
7.8

CVE-2021-1219 is a vulnerability in Cisco Smart Software Manager Satellite that allows authenticated local attackers to access static credentials stor...

Jan 20, 2021
CVE-2023-31173
7.7

This CVE describes a hard-coded credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator software on Windows. A...

Aug 31, 2023
CVE-2024-55927
7.6

This vulnerability in Xerox Workplace Suite allows attackers to predict or forge authentication tokens due to flawed token generation and hard-coded c...

Jan 23, 2025
CVE-2024-11147
7.6

ECOVACS robot lawnmowers and vacuums have a predictable root password generated from model and serial number, allowing attackers with shell access to ...

Jan 23, 2025
CVE-2025-40537
7.5

SolarWinds Web Help Desk contains hardcoded credentials that could allow attackers to access administrative functions under certain conditions. This a...

Jan 28, 2026
CVE-2021-47744
7.5

CVE-2021-47744 is a hard-coded credentials vulnerability in Cypress Solutions CTM-200/CTM-ONE devices running version 1.3.6. Attackers can use the sta...

Dec 31, 2025
CVE-2025-7358
7.5

CVE-2025-7358 is a hard-coded credentials vulnerability in Utarit Informatics Services Inc. SoliClub software that allows attackers to bypass authenti...

Dec 18, 2025
CVE-2025-1029
7.5

CVE-2025-1029 is a hard-coded credentials vulnerability in Utarit Information Services SoliClub software that allows attackers to extract sensitive au...

Dec 18, 2025
CVE-2025-41722
7.5

CVE-2025-41722 allows unauthenticated remote attackers to extract private keys from affected devices due to a hard-coded certificate used by the wsc s...

Oct 22, 2025
CVE-2025-7342
7.5

This vulnerability allows attackers with access to Kubernetes Image Builder build VMs to modify Windows images during creation, potentially injecting ...

Aug 17, 2025
CVE-2025-4130
7.5

PAVO Pay contains hard-coded credentials that can be extracted from the executable file, allowing attackers to gain unauthorized access to sensitive s...

Jul 21, 2025
CVE-2024-53357
7.5

Multiple SQL injection vulnerabilities in EasyVirt DCScope and CO2Scope allow authenticated attackers with low privileges to manipulate user, group, a...

Jan 31, 2025
CVE-2024-54749
7.5

Ubiquiti U7-Pro access points contain a hardcoded password in their firmware that could allow attackers to gain root access. This primarily affects us...

Dec 6, 2024
CVE-2024-41777
7.5

IBM Cognos Controller versions 11.0.0 and 11.0.1 contain hard-coded credentials that could be used for authentication, communication, or data encrypti...

Dec 3, 2024
CVE-2024-41161
7.5

CVE-2024-41161 is a critical authentication bypass vulnerability in Vonets industrial wifi bridge devices. Unauthenticated remote attackers can gain a...

Aug 8, 2024
CVE-2024-33329
7.5

CVE-2024-33329 is an authentication bypass vulnerability in Lumisxp content management system where attackers can use a hardcoded privileged ID to acc...

Jun 26, 2024
CVE-2024-32988
7.5

The OfferBox mobile applications for Android and iOS use a hard-coded secret key for JSON Web Token (JWT) authentication. This allows attackers who re...

May 22, 2024
CVE-2024-4844
7.5

This vulnerability allows attackers with administrative privileges on the Trellix ePolicy Orchestrator server to access the database encryption key by...

May 16, 2024

About CWE-798 (CWE-798)

Our database tracks 455 CVEs classified as CWE-798, with 261 rated critical and 146 rated high severity. The average CVSS score for CWE-798 vulnerabilities is 8.8.

External reference: View CWE-798 on MITRE CWE →

Monitor CWE-798 Vulnerabilities

Get alerted when new CWE-798 CVEs affect your infrastructure.

Start Monitoring Free