CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,755 vulnerabilities with CWE-798
CVE-2025-53754 MEDIUM
Digisol DG-GR6821AC Router - Privilege Escalation
CVE-2025-53842 MEDIUM
ZWX-2000CSW2-HN <0.3.19 - Info Disclosure
CVSS 4.5
CVE-2025-52376 CRITICAL
Nexxt Solutions NCM-X1800 Mesh Router <UV1.2.7 - Auth Bypass
CVSS 9.8
CVE-2025-3621 CRITICAL
ActADUR <2.0.2.0 - Command Injection
CVSS 9.6
CVE-2025-52363 MEDIUM
Tenda CP3 Pro Firmware V22.5.4.93 - Use of Hard-coded Credentials in /etc/passwd
CVSS 6.8
CVE-2025-7564 HIGH
LB-LINK BL-AC3600 1.0.22 - Hard-coded Credentials
CVSS 7.8
CVE-2025-7503 CRITICAL
OEM IP Camera <AppFHE1_V1.0.6.0 - Command Injection
CVE-2025-7401 CRITICAL
WordPress Premium Age Verification <3.0.2 - Info Disclosure
CVSS 9.8
CVE-2025-5023 HIGH
Mitsubishi Electric Corporation photovoltaic system monitor - Info ...
CVSS 7.1
CVE-2025-49551 HIGH
Adobe ColdFusion <= 2025.2, <= 2023.14, <= 2021.20 - Use of Hard-coded Credentials
CVSS 8.8
CVE-2025-37103 CRITICAL
HPE Networking Instant On - Auth Bypass
CVSS 9.8
CVE-2025-52492 HIGH
Paxton Paxton10 <4.6 SR6 - Info Disclosure
CVSS 7.5
CVE-2025-7079 LOW
mao888 bluebell-plus < 2.3.0 - Hard-coded Password in JWT Token Handler
CVSS 3.7
CVE-2025-45813 CRITICAL
ENENSYS IPGuard v2 2.10.0 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2025-20309 CRITICAL
Cisco Unified Communications Manager - Unauthenticated Remote Code Execution via Hard-coded Root Credentials
CVSS 10.0
CVE-2025-4378 CRITICAL
Ataturk University ATA-AOF Mobile App <20.06.2025 - Auth Bypass
CVSS 10.0
CVE-2025-34034 HIGH
Blue Angel Software Suite - Info Disclosure
CVSS 8.8
CVE-2025-45784 CRITICAL
D-Link DPH-400S/SE VoIP Phone 1.01 - Hardcoded Credentials Exposure via Firmware Binary
CVSS 9.8
CVE-2025-34509 HIGH
Sitecore XP/XM 10.1-10.1.4, 10.2, 10.3-10.3.3, 10.4-10.4.1 - Unauthenticated RCE via Hardcoded Credentials
CVSS 7.5
CVE-2025-28388 CRITICAL
OpenC3 COSMOS < 6.0.2 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2025-35940 HIGH
GFI Archiver 15.7-15.8 - Unauthenticated JWT Token Forgery via Hard-coded Signing Key
CVSS 8.1
CVE-2025-5751 MEDIUM
WOLFBOX Level 2 EV Charger Management Card - Unauthenticated Authentication Bypass via Hard-coded Credentials
CVSS 6.8
CVE-2025-3321 CRITICAL
Predefined Administrative Account - Info Disclosure
CVE-2025-5379 MEDIUM
NuCom NC-WR744G 8.5.5 Build 20200530.307 - Hard-Coded Credentials
CVSS 4.3
CVE-2025-4633 MEDIUM
Airpointer 2.4.107-2 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 1,755
Exploit Likelihood High