CWE-321

High likelihood

Use of Hard-coded Cryptographic Key

Parent: CWE-798 - Use of Hard-coded Credentials

The product uses a hard-coded, unchangeable cryptographic key.

311 vulnerabilities with CWE-321
CVE-2025-46582 HIGH
ZTE ZXMP M721 >=ZXMPM721V5.30.020.001P01 - Authenticated Private Key Disclosure
CVSS 7.7
CVE-2025-34500 HIGH
Deck Mate 2 < all known versions prior to 2025-10-23 - Arbitrary Code Execution via Insecure Firmware Update Chain
CVE-2025-56802 MEDIUM
Reolink desktop app - Info Disclosure
CVSS 5.1
CVE-2025-56801 MEDIUM
Reolink Desktop App 8.18.12 - Info Disclosure
CVSS 5.1
CVE-2025-11899 HIGH
Agentflow - Unauthenticated Authentication Bypass via Hard-coded Cryptographic Key
CVSS 8.1
CVE-2025-58426 MEDIUM
desknet's NEO <9.0R2.0 - Code Injection
CVSS 4.3
CVE-2025-11609 LOW
Code-projects Hospital Management System 1.0 - Code Injection
CVSS 3.7
CVE-2025-35052 MEDIUM
Newforma Info Exchange - Path Traversal
CVSS 5.3
CVE-2025-11290 MEDIUM
CRMEB < 5.6.1 - Use of Hard-coded Cryptographic Key in JWT HMAC Secret Handler
CVSS 5.6
CVE-2025-59407 CRITICAL
Flock Safety DetectionProcessing 6.35.33 - Info Disclosure
CVSS 9.8
CVE-2025-24525 HIGH
Keysight Ixia Vision <6.9.1 - Info Disclosure
CVSS 7.5
CVE-2025-34217 CRITICAL
Vasion Print - Privilege Escalation
CVSS 9.8
CVE-2025-8625 CRITICAL
Copypress Rest API 1.1-1.2 - Unauthenticated Remote Code Execution via JWT Token Forgery
CVSS 9.8
CVE-2025-34234 HIGH
Vasion Print <25.1.102-25.1.1413 - Info Disclosure
CVSS 7.5
CVE-2025-34215 CRITICAL
Vasion Print Virtual Appliance < 22.0.1026 / Application < 20.0.2702 - RCE via Firmware Update
CVSS 9.8
CVE-2025-34211 MEDIUM
Vasion Print <22.0.1049-20.0.2786 - Info Disclosure
CVSS 4.9
CVE-2025-36326 LOW
IBM Cognos Controller <11.0.1 - Info Disclosure
CVSS 3.7
CVE-2025-60250 MEDIUM
Unitree Go2, G1, H1, B2 - Info Disclosure
CVSS 4.7
CVE-2025-58069 MEDIUM
Click Plus PLC <3.60 - Info Disclosure
CVSS 5.3
CVE-2025-54807 CRITICAL
Device Firmware <unknown - Auth Bypass
CVSS 9.8
CVE-2025-55112 HIGH
Control-M/Agent <9.0.20 - Info Disclosure
CVSS 7.4
CVE-2025-57174 CRITICAL
Siklu Communications Etherhaul - RCE
CVSS 9.8
CVE-2025-10250 MEDIUM
DJI Mavic Spark, Mavic Air and Mavic Mini <01.00.0500 - Info Disclo...
CVSS 5.0
CVE-2025-10080 LOW
Running-elephant Datart <1.0.0-rc3 - Info Disclosure
CVSS 3.1
CVE-2025-30200 MEDIUM
ECOVACS DEEBOT Firmware - Use of Hard-coded Cryptographic Key in Wi-Fi Communication
CVSS 6.3
Details
Vulnerabilities 311
Exploit Likelihood High