CWE-321

High likelihood

Use of Hard-coded Cryptographic Key

Parent: CWE-798 - Use of Hard-coded Credentials

The product uses a hard-coded, unchangeable cryptographic key.

311 vulnerabilities with CWE-321
CVE-2026-5456 LOW
Align Technology My Invisalign App com.aligntech.myinvisalign.emea BuildConfig.java hard-coded key
CVSS 3.3
CVE-2026-5455 LOW
Dialogue App ca.diagram.dialogue config.json hard-coded key
CVSS 3.3
CVE-2026-5454 LOW
GRID Organiser App co.gridapp.organiser app.json hard-coded key
CVSS 3.3
CVE-2026-5453 LOW
Rico só vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-coded key
CVSS 3.3
CVE-2026-5452 LOW
UCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded key
CVSS 3.3
CVE-2026-5420 LOW
Shinrays Games Goods Triple App cats.goods.sort.sorting.games jRwTX.java hard-coded key
CVSS 2.5
CVE-2026-5310 LOW
Enter Software Iperius Backup IperiusAccounts.ini hard-coded key
CVSS 2.5
CVE-2026-4588 LOW
kalcaddle kodbox Site-level API key shareOut.class.php shareSafeGroup hard-coded key
CVSS 3.7
CVE-2026-4477 LOW
Yi Technology YI Home Camera WPA/WPS hard-coded key
CVSS 3.1
CVE-2026-3963 LOW
perfree go-fastdfs-web <=1.3.7 - Auth Bypass
CVSS 3.7
CVE-2026-0754 HIGH
Poly Voice - Use of Hard-coded Cryptographic Key
CVE-2026-1442 HIGH
Unitree Go2 and Go1 Firmware - Use of Hard-coded Cryptographic Key
CVSS 7.8
CVE-2026-27519 HIGH
Binardat 10G08-0800GSM <V300SP10260209 - Info Disclosure
CVSS 7.5
CVE-2026-26335 CRITICAL
Calero VeraSMART <2022 R1 - Remote Code Execution
CVSS 9.8
CVE-2026-25894 CRITICAL
FUXA <1.2.9 - Remote Code Execution
CVSS 9.8
CVE-2026-22906 CRITICAL
User Credentials Storage - Info Disclosure
CVSS 9.8
CVE-2026-2103 HIGH
Infor SyteLine ERP - Info Disclosure
CVSS 7.1
CVE-2026-25505 CRITICAL
bambuddy < 0.1.7 - Unauthenticated Use of Hard-coded Cryptographic Key
CVSS 9.8
CVE-2026-22586 CRITICAL
Salesforce Marketing Cloud Engagement - Web Services Protocol Manip...
CVSS 9.8
CVE-2025-40946 HIGH
Siemens blueplanet - Use of Hard-coded Cryptographic Key for Technical Service Credentials
CVSS 8.3
CVE-2025-55449 HIGH
AstrBotDevs AstrBot 3.5.15 - Auth Bypass
CVSS 7.3
CVE-2025-15605 HIGH
Hardcoded Cryptographic Key in Configuration Encryption Mechanism on TP-Link Archer NX200, NX210, NX500 and NX600
CVSS 7.3
CVE-2025-67112 CRITICAL
Small Cell Sercomm SCE4255W <DG3934v3@2308041842 - Privilege Escalation
CVSS 9.8
CVE-2025-14923 MEDIUM
IBM WebSphere Liberty 17.0.0.3-26.0.0.2 - Auth Bypass
CVSS 4.7
CVE-2025-67305 CRITICAL
RUCKUS Network Director <4.5.0.56 - Auth Bypass
CVSS 9.8
Details
Vulnerabilities 311
Exploit Likelihood High