CWE-321

High likelihood

Use of Hard-coded Cryptographic Key

Parent: CWE-798 - Use of Hard-coded Credentials

The product uses a hard-coded, unchangeable cryptographic key.

297 vulnerabilities with CWE-321
CVE-2026-26335 CRITICAL
Calero VeraSMART <2022 R1 - Remote Code Execution
CVSS 9.8
CVE-2026-25894 CRITICAL
FUXA <1.2.9 - Remote Code Execution
CVSS 9.8
CVE-2026-22906 CRITICAL
User Credentials Storage - Info Disclosure
CVSS 9.8
CVE-2026-2103 HIGH
Infor SyteLine ERP - Info Disclosure
CVSS 7.1
CVE-2026-25505 CRITICAL
bambuddy < 0.1.7 - Unauthenticated Use of Hard-coded Cryptographic Key
CVSS 9.8
CVE-2026-22586 CRITICAL
Salesforce Marketing Cloud Engagement - Web Services Protocol Manip...
CVSS 9.8
CVE-2025-40946 HIGH
Siemens blueplanet - Use of Hard-coded Cryptographic Key for Technical Service Credentials
CVSS 8.3
CVE-2025-55449 HIGH
AstrBotDevs AstrBot 3.5.15 - Auth Bypass
CVSS 7.3
CVE-2025-15605 HIGH
Hardcoded Cryptographic Key in Configuration Encryption Mechanism on TP-Link Archer NX200, NX210, NX500 and NX600
CVSS 7.3
CVE-2025-67112 CRITICAL
Small Cell Sercomm SCE4255W <DG3934v3@2308041842 - Privilege Escalation
CVSS 9.8
CVE-2025-14923 MEDIUM
IBM WebSphere Liberty 17.0.0.3-26.0.0.2 - Auth Bypass
CVSS 4.7
CVE-2025-67305 CRITICAL
RUCKUS Network Director <4.5.0.56 - Auth Bypass
CVSS 9.8
CVE-2025-58740 MEDIUM
Milner ImageDirector Capture <7.6.3.25808 - Info Disclosure
CVSS 5.5
CVE-2025-62581 CRITICAL
Delta Electronics DIAView - Hard-Coded Cryptographic Key
CVSS 9.8
CVE-2025-15108 LOW
PandaXGO PandaX <fb8ff40f7ce5dfebdf66306c6d85625061faf7e5 - Unknown...
CVSS 3.7
CVE-2025-15107 LOW
Actiontech SQLE <=4.2511.0 - Use of Hard-coded Cryptographic Key
CVSS 3.7
CVE-2025-15105 LOW
maxun < 0.0.28 - Use of Hard-coded Cryptographic Key via api_key Argument
CVSS 3.7
CVE-2025-68948 HIGH
SiYuan < 3.5.2 - Session Hijacking via Hardcoded Cryptographic Key
CVSS 8.1
CVE-2025-52601 HIGH
Hanwha Vision XNO/XNV/XND/XNB/XNF Firmware < 2.24.00 - Use of Hard-coded Cryptographic Key
CVSS 7.8
CVE-2025-15016 CRITICAL
Enterprise Cloud Database - Info Disclosure
CVSS 9.8
CVE-2025-15005 LOW
CouchCMS < 2.4 - Use of Hard-coded Cryptographic Key in reCAPTCHA Handler
CVSS 3.7
CVE-2025-14651 LOW
MartialBE one-hub <0.14.27 - Code Injection
CVSS 3.7
CVE-2025-54947 CRITICAL
Apache StreamPark 2.0.0-2.1.7 - Use of Hard-coded Cryptographic Key
CVSS 9.8
CVE-2025-34256 CRITICAL
Advantech WISE-DeviceOn Server <5.4 - Auth Bypass
CVSS 9.8
CVE-2025-13948 MEDIUM
opsre go-ldap-admin <20251011 - Info Disclosure
CVSS 5.6
Details
Vulnerabilities 297
Exploit Likelihood High