CWE-798: CWE-798
Yearly Trend
Top Affected Vendors
All CWE-798 CVEs (456)
The Hitron CODA-5310 router contains hard-coded encryption keys in its firmware, allowing authenticated administrators to decrypt system files. This e...
Jun 2, 2023This vulnerability involves hard-coded credentials in STARDOM FCN and FCJ controllers, allowing attackers with administrative access to read/change co...
Jun 28, 2022ControlUp Real-Time Agent versions before 8.2.5 contain a hardcoded cryptographic key that allows attackers to authenticate to the WCF channel and exe...
Jan 4, 2022This vulnerability allows attackers to gain administrative access to Brocade SANnav's PostgreSQL database using a hard-coded weak password ('passw0rd'...
Jun 9, 2021This vulnerability in DOXENSE WATCHDOC allows attackers to obtain private user puk codes for Active Directory registered users due to hard-coded and p...
Sep 26, 2025This vulnerability allows attackers within Wi-Fi range of Mitsubishi Electric's discontinued EcoGuideTAB photovoltaic monitors to access hardcoded cre...
Jul 10, 2025CVE-2024-27168 is an authentication bypass vulnerability in Toshiba multifunction printers where hardcoded private keys are used for internal API auth...
Jun 14, 2024ABB FLXEON devices contain hard-coded credentials that could allow attackers to gain unauthorized access. This affects all FLXEON versions through 9.3...
Sep 17, 2025Tenda CP3 Pro routers with firmware V22.5.4.93 contain a hardcoded root password hash in system files, allowing attackers who can access the firmware ...
Jul 14, 2025This vulnerability allows physically present attackers to bypass authentication on WOLFBOX Level 2 EV Charger Management Cards using hard-coded creden...
Jun 6, 2025GNCC's GC2 Indoor Security Camera 1080P has a hardcoded identical root password across all devices, allowing attackers with physical access to gain ad...
Aug 15, 2024DCIM dcTrack platforms use default and hard-coded credentials that allow attackers to gain administrative access. This vulnerability enables database ...
Dec 4, 2025IBM Concert versions 1.0.0 through 2.1.0 contain hard-coded credentials that could allow remote attackers to authenticate to the system without proper...
Feb 17, 2026Open5GS WebUI uses a hard-coded JWT signing key ('change-me') when the JWT_SECRET_KEY environment variable is not set, allowing attackers to forge aut...
Jan 20, 2026This CVE involves hardcoded credentials in the ATLAS-EPIC software, allowing attackers to gain unauthorized access to systems running vulnerable versi...
Oct 16, 2025CVE-2025-4633 allows unauthenticated attackers to access Airpointer 2.4.107-2 web portals using default credentials. This affects all deployments usin...
May 30, 2025Dell PowerStore version 4.0.0.0 contains hard-coded credentials in its image file, allowing attackers with knowledge of these credentials to gain unau...
May 28, 2025This vulnerability allows attackers to access administrative/debug scripts in the web interface using undocumented hard-coded credentials. This provid...
May 21, 2025The IROAD dashcam mobile application contains hardcoded credentials that allow attackers on the same Wi-Fi network to access API endpoints and retriev...
Mar 18, 2025This vulnerability exposes Artifactory API keys in IBM Cognos Controller and IBM Controller, allowing authenticated users to publish code to private p...
Jan 7, 2025Aptos Wisal payroll accounting software before version 7.1.6 uses hardcoded credentials in its Windows client to retrieve all usernames and passwords ...
May 24, 2024SolarWinds Access Rights Manager (ARM) contains hard-coded credentials that allow authentication bypass to the RabbitMQ management console. This vulne...
Sep 12, 2024This critical vulnerability in Go-Tribe's gotribe software involves hard-coded credentials in the token signing function. Attackers can exploit this t...
Aug 24, 2024Toshiba printers use a hardcoded encryption key in a shell script to encrypt logs, allowing attackers to decrypt sensitive log files. This vulnerabili...
Jun 14, 2024This vulnerability in Keycloak allows sensitive runtime values like passwords to be captured during the build process and embedded as default values i...
Nov 25, 2024SolarWinds Database Performance Analyzer contains a hard-coded cryptographic key that could enable machine-in-the-middle attacks if exploited. This af...
Aug 12, 2025CVE-2025-23179 involves hard-coded credentials in software, allowing attackers to bypass authentication using embedded default passwords or keys. This...
Apr 29, 2025This vulnerability in SunGrow WiNet-S inverters allows attackers to send arbitrary commands to inverters using hardcoded MQTT credentials and intercep...
Jan 24, 2025Weintek cMT-3072XH2 HMI devices contain a hardcoded encryption key in easyweb v2.1.53 and OS v20231011, allowing attackers to decrypt sensitive inform...
Mar 3, 2026This vulnerability exposes password hashes for system accounts within firmware update files. Remote attackers could recover credentials and gain unaut...
Jan 15, 2026This vulnerability involves hard-coded configuration values in Desktop Alert PingAlert's Application Server, which could allow attackers to bypass sec...
Nov 24, 2025This vulnerability involves hard-coded credentials in Fortinet FortiWeb web application firewalls that could allow authenticated attackers with shell ...
Nov 18, 2025CVE-2025-64766 is a hard-coded secret vulnerability in NixOS's OnlyOffice document server module that allows attackers with knowledge of a document re...
Nov 17, 2025The Helpie FAQ WordPress plugin versions up to 1.39 contain hard-coded credentials that allow attackers to retrieve embedded sensitive data. This affe...
Sep 22, 2025This CVE describes a hard-coded credentials vulnerability in the Estonian Shipping Methods for WooCommerce WordPress plugin. Attackers can retrieve em...
Sep 22, 2025A hard-coded credentials vulnerability in weDevs WP Project Manager WordPress plugin allows attackers to retrieve embedded sensitive data. This affect...
Sep 22, 2025MXsecurity software versions v1.1.0 and prior contain hard-coded credentials that could allow attackers to access and tamper with sensitive data. This...
Oct 18, 2024This vulnerability allows an authenticated attacker with administrative credentials to inject malicious scripts into Cisco Prime Infrastructure's web ...
Feb 4, 2026This CVE describes a hardcoded credential vulnerability in TeleMessage's archiving backend that accepts API calls with static username 'logfile' and p...
May 8, 2025Cybele Software Thinfinity Workspace versions before 7.0.2.113 contain a hardcoded cryptographic key used for encryption. This vulnerability allows at...
Nov 13, 2024Zimbra Collaboration 10.0 and 10.1 contain hardcoded Flickr API credentials in the publicly accessible Flickr Zimlet. Attackers can retrieve these cre...
Dec 15, 2025This vulnerability allows attackers to use an undocumented UART port on the PCB as a side-channel to gain read access to parts of the device's filesys...
Dec 9, 2025The Xtooltech Xtool AnyScan Android application uses hardcoded cryptographic keys to decrypt update metadata, allowing attackers who intercept network...
Nov 24, 2025IBM MaaS360 for Android versions 6.31 through 8.60 contain hard-coded credentials that can be extracted by anyone with physical access to the device. ...
Aug 29, 2024This vulnerability allows attackers with physical access to extract WPA/WPS credentials stored in plaintext within the SyroTech SY-GPON-1110-WDONT rou...
Jul 26, 2024This CVE describes a use of hard-coded credentials vulnerability in ZWX-2000CSW2-HN and ZWX-2000CS2-HN firmware. Attackers can exploit this to obtain ...
Jul 16, 2025This vulnerability involves hard-coded credentials embedded in the application binary that are used for authentication and communication with a mobile...
Jan 17, 2025The Piccoma mobile app for Android and iOS versions before 6.20.0 contains a hard-coded API key for an external service. This allows local attackers w...
Jul 1, 2024Dormakaba's FWServiceTool uses a static, hardcoded password to decrypt encrypted ZIP files containing firmware updates for Access Managers. This allow...
Jan 26, 2026CVE-2025-59096 is a hard-coded credential vulnerability in Kaba 9300 Administration software that allows attackers to gain administrative access using...
Jan 26, 2026About CWE-798 (CWE-798)
Our database tracks 456 CVEs classified as CWE-798, with 262 rated critical and 146 rated high severity. The average CVSS score for CWE-798 vulnerabilities is 8.8.
External reference: View CWE-798 on MITRE CWE →
Monitor CWE-798 Vulnerabilities
Get alerted when new CWE-798 CVEs affect your infrastructure.
Start Monitoring Free