CWE-321

High likelihood

Use of Hard-coded Cryptographic Key

Parent: CWE-798 - Use of Hard-coded Credentials

The product uses a hard-coded, unchangeable cryptographic key.

311 vulnerabilities with CWE-321
CVE-2026-5846 MEDIUM
Hard-coded Cryptographic Key in Watchfire Signs Controllers
CVSS 5.7
CVE-2026-54363 CRITICAL
CentreStack < 17.5 Hardcoded Key Token Forgery RCE
CVSS 9.1
CVE-2026-14932 MEDIUM
Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart
CVSS 6.5
CVE-2026-13184 HIGH
RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX
CVSS 7.5
CVE-2026-47410 CRITICAL
praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
CVSS 9.8
CVE-2026-62241 CRITICAL
clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery
CVSS 9.1
CVE-2026-9770 HIGH
Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link Kasa EC70 and EC71
CVE-2026-56271 CRITICAL
Flowise - Weak Default JWT Secrets in Authentication Middleware
CVSS 9.8
CVE-2026-57172 HIGH
DataEase: Hardcoded JWT Signing Secret in ShareLink
CVE-2026-39031 MEDIUM
Lansweeper lsrunase 2.0 and lsencrypt 2.0 - Credential Exposure via Hardcoded RC4 Key
CVSS 5.5
CVE-2026-54833 HIGH
WordPress Enable CORS plugin <= 2.0.3 - Backdoor vulnerability
CVSS 7.4
CVE-2026-9220 HIGH
Setracker2 Children's Smartwatch Ecosystem Use of hard-coded cryptographic key
CVSS 7.5
CVE-2026-35019 HIGH
NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass
CVSS 8.1
CVE-2026-9260 MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Use of Hard-coded Cryptographic Key
CVSS 6.2
CVE-2026-34029 MEDIUM
Wertheim SafeController 6.15.8328.28014 - Hard-Coded Key Information Disclosure
CVE-2026-34022 HIGH
Weak custom cryptography and hard-coded keys in Wertheim SafeController 65000 allow traffic decryption
CVE-2026-28742 CRITICAL
Naxclow IoT Platform Use of hard-coded cryptographic key
CVSS 9.8
CVE-2026-50091 CRITICAL
Aqara Home Android SDK hardcoded keys
CVSS 9.1
CVE-2026-11505 MEDIUM
GL.iNet XE3000 glnassys hard-coded key
CVSS 5.0
CVE-2026-46395 CRITICAL
HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
CVE-2026-11347 HIGH
Hardcoded Cryptographic Keys and Weak IV Generation in Linqi Application
CVE-2026-45433 HIGH
GX Earth ONT Models - Hardcoded RSA Private Key
CVE-2026-50226 MEDIUM
Acer Connect M6E 5G Portable WiFi Router - Firmware Theft & IMEI Spoofing via Connect-OTA
CVSS 5.3
CVE-2026-45041 HIGH
RustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgery
CVE-2026-24218 HIGH
NVIDIA DGX Spark < OTA0 - Use of Hard-coded Cryptographic Key in Factory Provisioning Process
CVSS 8.1
Details
Vulnerabilities 311
Exploit Likelihood High