CWE-798: CWE-798

456
Total CVEs
262
Critical
146
High
8.8
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
24
2025
100
2024
97
2023
66
2022
69

Top Affected Vendors

1 Ibm 20
2 Fiberhome 15
3 Dlink 14
4 Totolink 7
5 Siemens 6
6 Schneider Electric 6
7 Cisco 5
8 Solarwinds 5
9 Fortinet 4
10 Tenda 4

All CWE-798 CVEs (456)

CVE-2022-47617
7.2

The Hitron CODA-5310 router contains hard-coded encryption keys in its firmware, allowing authenticated administrators to decrypt system files. This e...

Jun 2, 2023
CVE-2022-30997
7.2

This vulnerability involves hard-coded credentials in STARDOM FCN and FCJ controllers, allowing attackers with administrative access to read/change co...

Jun 28, 2022
CVE-2021-45913
7.2

ControlUp Real-Time Agent versions before 8.2.5 contain a hardcoded cryptographic key that allows attackers to authenticate to the WCF channel and exe...

Jan 4, 2022
CVE-2020-15382
7.2

This vulnerability allows attackers to gain administrative access to Brocade SANnav's PostgreSQL database using a hard-coded weak password ('passw0rd'...

Jun 9, 2021
CVE-2025-58385
7.1

This vulnerability in DOXENSE WATCHDOC allows attackers to obtain private user puk codes for Active Directory registered users due to hard-coded and p...

Sep 26, 2025
CVE-2025-5023
7.1

This vulnerability allows attackers within Wi-Fi range of Mitsubishi Electric's discontinued EcoGuideTAB photovoltaic monitors to access hardcoded cre...

Jul 10, 2025
CVE-2024-27168
7.1

CVE-2024-27168 is an authentication bypass vulnerability in Toshiba multifunction printers where hardcoded private keys are used for internal API auth...

Jun 14, 2024
CVE-2024-48842
7.0

ABB FLXEON devices contain hard-coded credentials that could allow attackers to gain unauthorized access. This affects all FLXEON versions through 9.3...

Sep 17, 2025
CVE-2025-52363
6.8

Tenda CP3 Pro routers with firmware V22.5.4.93 contain a hardcoded root password hash in system files, allowing attackers who can access the firmware ...

Jul 14, 2025
CVE-2025-5751
6.8

This vulnerability allows physically present attackers to bypass authentication on WOLFBOX Level 2 EV Charger Management Cards using hard-coded creden...

Jun 6, 2025
CVE-2024-31798
6.8

GNCC's GC2 Indoor Security Camera 1080P has a hardcoded identical root password across all devices, allowing attackers with physical access to gain ad...

Aug 15, 2024
CVE-2025-66237
6.7

DCIM dcTrack platforms use default and hard-coded credentials that allow attackers to gain administrative access. This vulnerability enables database ...

Dec 4, 2025
CVE-2025-33089
6.5

IBM Concert versions 1.0.0 through 2.1.0 contain hard-coded credentials that could allow remote attackers to authenticate to the system without proper...

Feb 17, 2026
CVE-2026-0622
6.5

Open5GS WebUI uses a hard-coded JWT signing key ('change-me') when the JWT_SECRET_KEY environment variable is not set, allowing attackers to forge aut...

Jan 20, 2026
CVE-2025-60639
6.5

This CVE involves hardcoded credentials in the ATLAS-EPIC software, allowing attackers to gain unauthorized access to systems running vulnerable versi...

Oct 16, 2025
CVE-2025-4633
6.5

CVE-2025-4633 allows unauthenticated attackers to access Airpointer 2.4.107-2 web portals using default credentials. This affects all deployments usin...

May 30, 2025
CVE-2025-36572
6.5

Dell PowerStore version 4.0.0.0 contains hard-coded credentials in its image file, allowing attackers with knowledge of these credentials to gain unau...

May 28, 2025
CVE-2025-48414
6.5

This vulnerability allows attackers to access administrative/debug scripts in the web interface using undocumented hard-coded credentials. This provid...

May 21, 2025
CVE-2025-30109
6.5

The IROAD dashcam mobile application contains hardcoded credentials that allow attackers on the same Wi-Fi network to access API endpoints and retriev...

Mar 18, 2025
CVE-2024-28778
6.5

This vulnerability exposes Artifactory API keys in IBM Cognos Controller and IBM Controller, allowing authenticated users to publish code to private p...

Jan 7, 2025
CVE-2024-36049
6.5

Aptos Wisal payroll accounting software before version 7.1.6 uses hardcoded credentials in its Windows client to retrieve all usernames and passwords ...

May 24, 2024
CVE-2024-28990
6.3

SolarWinds Access Rights Manager (ARM) contains hard-coded credentials that allow authentication bypass to the RabbitMQ management console. This vulne...

Sep 12, 2024
CVE-2024-8135
6.3

This critical vulnerability in Go-Tribe's gotribe software involves hard-coded credentials in the token signing function. Attackers can exploit this t...

Aug 24, 2024
CVE-2024-27160
6.2

Toshiba printers use a hardcoded encryption key in a shell script to encrypt logs, allowing attackers to decrypt sensitive log files. This vulnerabili...

Jun 14, 2024
CVE-2024-10451
5.9

This vulnerability in Keycloak allows sensitive runtime values like passwords to be captured during the build process and embedded as default values i...

Nov 25, 2024
CVE-2025-26398
5.6

SolarWinds Database Performance Analyzer contains a hard-coded cryptographic key that could enable machine-in-the-middle attacks if exploited. This af...

Aug 12, 2025
CVE-2025-23179
5.5

CVE-2025-23179 involves hard-coded credentials in software, allowing attackers to bypass authentication using embedded default passwords or keys. This...

Apr 29, 2025
CVE-2024-50692
5.4

This vulnerability in SunGrow WiNet-S inverters allows attackers to send arbitrary commands to inverters using hardcoded MQTT credentials and intercep...

Jan 24, 2025
CVE-2024-55023
5.3

Weintek cMT-3072XH2 HMI devices contain a hardcoded encryption key in easyweb v2.1.53 and OS v20231011, allowing attackers to decrypt sensitive inform...

Mar 3, 2026
CVE-2026-22911
5.3

This vulnerability exposes password hashes for system accounts within firmware update files. Remote attackers could recover credentials and gain unaut...

Jan 15, 2026
CVE-2025-54341
5.3

This vulnerability involves hard-coded configuration values in Desktop Alert PingAlert's Application Server, which could allow attackers to bypass sec...

Nov 24, 2025
CVE-2025-59669
5.3

This vulnerability involves hard-coded credentials in Fortinet FortiWeb web application firewalls that could allow authenticated attackers with shell ...

Nov 18, 2025
CVE-2025-64766
5.3

CVE-2025-64766 is a hard-coded secret vulnerability in NixOS's OnlyOffice document server module that allows attackers with knowledge of a document re...

Nov 17, 2025
CVE-2025-58659
5.3

The Helpie FAQ WordPress plugin versions up to 1.39 contain hard-coded credentials that allow attackers to retrieve embedded sensitive data. This affe...

Sep 22, 2025
CVE-2025-58656
5.3

This CVE describes a hard-coded credentials vulnerability in the Estonian Shipping Methods for WooCommerce WordPress plugin. Attackers can retrieve em...

Sep 22, 2025
CVE-2025-58269
5.3

A hard-coded credentials vulnerability in weDevs WP Project Manager WordPress plugin allows attackers to retrieve embedded sensitive data. This affect...

Sep 22, 2025
CVE-2024-4740
5.3

MXsecurity software versions v1.1.0 and prior contain hard-coded credentials that could allow attackers to access and tamper with sensitive data. This...

Oct 18, 2024
CVE-2026-20111
4.8

This vulnerability allows an authenticated attacker with administrative credentials to inject malicious scripts into Cisco Prime Infrastructure's web ...

Feb 4, 2026
CVE-2025-47730
4.8

This CVE describes a hardcoded credential vulnerability in TeleMessage's archiving backend that accepts API calls with static username 'logfile' and p...

May 8, 2025
CVE-2024-40410
4.8

Cybele Software Thinfinity Workspace versions before 7.0.2.113 contain a hardcoded cryptographic key used for encryption. This vulnerability allows at...

Nov 13, 2024
CVE-2025-67809
4.7

Zimbra Collaboration 10.0 and 10.1 contain hardcoded Flickr API credentials in the publicly accessible Flickr Zimlet. Attackers can retrieve these cre...

Dec 15, 2025
CVE-2025-41696
4.6

This vulnerability allows attackers to use an undocumented UART port on the PCB as a side-channel to gain read access to parts of the device's filesys...

Dec 9, 2025
CVE-2025-63433
4.6

The Xtooltech Xtool AnyScan Android application uses hardcoded cryptographic keys to decrypt update metadata, allowing attackers who intercept network...

Nov 24, 2025
CVE-2024-35118
4.6

IBM MaaS360 for Android versions 6.31 through 8.60 contain hard-coded credentials that can be extracted by anyone with physical access to the device. ...

Aug 29, 2024
CVE-2024-41689
4.6

This vulnerability allows attackers with physical access to extract WPA/WPS credentials stored in plaintext within the SyroTech SY-GPON-1110-WDONT rou...

Jul 26, 2024
CVE-2025-53842
4.5

This CVE describes a use of hard-coded credentials vulnerability in ZWX-2000CSW2-HN and ZWX-2000CS2-HN firmware. Attackers can exploit this to obtain ...

Jul 16, 2025
CVE-2024-45832
4.3

This vulnerability involves hard-coded credentials embedded in the application binary that are used for authentication and communication with a mobile...

Jan 17, 2025
CVE-2024-38480
4.0

The Piccoma mobile app for Android and iOS versions before 6.20.0 contains a hard-coded API key for an external service. This allows local attackers w...

Jul 1, 2024
CVE-2025-59107
N/A

Dormakaba's FWServiceTool uses a static, hardcoded password to decrypt encrypted ZIP files containing firmware updates for Access Managers. This allow...

Jan 26, 2026
CVE-2025-59096
N/A

CVE-2025-59096 is a hard-coded credential vulnerability in Kaba 9300 Administration software that allows attackers to gain administrative access using...

Jan 26, 2026

About CWE-798 (CWE-798)

Our database tracks 456 CVEs classified as CWE-798, with 262 rated critical and 146 rated high severity. The average CVSS score for CWE-798 vulnerabilities is 8.8.

External reference: View CWE-798 on MITRE CWE →

Monitor CWE-798 Vulnerabilities

Get alerted when new CWE-798 CVEs affect your infrastructure.

Start Monitoring Free