CWE-321
High likelihoodUse of Hard-coded Cryptographic Key
The product uses a hard-coded, unchangeable cryptographic key.
311 vulnerabilities with CWE-321
CVE-2026-5846
MEDIUM
Hard-coded Cryptographic Key in Watchfire Signs Controllers
CVSS 5.7
CVE-2026-54363
CRITICAL
CentreStack < 17.5 Hardcoded Key Token Forgery RCE
CVSS 9.1
CVE-2026-14932
MEDIUM
Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart
CVSS 6.5
CVE-2026-13184
HIGH
RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX
CVSS 7.5
CVE-2026-47410
CRITICAL
praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
CVSS 9.8
CVE-2026-62241
CRITICAL
clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery
CVSS 9.1
CVE-2026-9770
HIGH
Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link Kasa EC70 and EC71
CVE-2026-56271
CRITICAL
Flowise - Weak Default JWT Secrets in Authentication Middleware
CVSS 9.8
CVE-2026-57172
HIGH
DataEase: Hardcoded JWT Signing Secret in ShareLink
CVE-2026-39031
MEDIUM
Lansweeper lsrunase 2.0 and lsencrypt 2.0 - Credential Exposure via Hardcoded RC4 Key
CVSS 5.5
CVE-2026-54833
HIGH
WordPress Enable CORS plugin <= 2.0.3 - Backdoor vulnerability
CVSS 7.4
CVE-2026-9220
HIGH
Setracker2 Children's Smartwatch Ecosystem Use of hard-coded cryptographic key
CVSS 7.5
CVE-2026-35019
HIGH
NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass
CVSS 8.1
CVE-2026-9260
MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Use of Hard-coded Cryptographic Key
CVSS 6.2
CVE-2026-34029
MEDIUM
Wertheim SafeController 6.15.8328.28014 - Hard-Coded Key Information Disclosure
CVE-2026-34022
HIGH
Weak custom cryptography and hard-coded keys in Wertheim SafeController 65000 allow traffic decryption
CVE-2026-28742
CRITICAL
Naxclow IoT Platform Use of hard-coded cryptographic key
CVSS 9.8
CVE-2026-50091
CRITICAL
Aqara Home Android SDK hardcoded keys
CVSS 9.1
CVE-2026-11505
MEDIUM
GL.iNet XE3000 glnassys hard-coded key
CVSS 5.0
CVE-2026-46395
CRITICAL
HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
CVE-2026-11347
HIGH
Hardcoded Cryptographic Keys and Weak IV Generation in Linqi Application
CVE-2026-45433
HIGH
GX Earth ONT Models - Hardcoded RSA Private Key
CVE-2026-50226
MEDIUM
Acer Connect M6E 5G Portable WiFi Router - Firmware Theft & IMEI Spoofing via Connect-OTA
CVSS 5.3
CVE-2026-45041
HIGH
RustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgery
CVE-2026-24218
HIGH
NVIDIA DGX Spark < OTA0 - Use of Hard-coded Cryptographic Key in Factory Provisioning Process
CVSS 8.1
Details
Vulnerabilities
311
Exploit Likelihood
High