CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,755 vulnerabilities with CWE-798
CVE-2025-48491 LOW
Project AI <pre-beta - Info Disclosure
CVE-2025-46352 CRITICAL
CS5000 Fire Panel - Info Disclosure
CVSS 9.8
CVE-2025-48748 CRITICAL
Netwrix Directory Manager <10.0.7784.0 - Info Disclosure
CVSS 10.0
CVE-2025-36572 MEDIUM
Dell PowerStoreOS < 4.0.1.3-2494147 - Use of Hard-coded Credentials in Image File
CVSS 6.5
CVE-2025-5164 LOW
PerfreeBlog 4.0.11 - Code Injection
CVSS 3.7
CVE-2025-41380 MEDIUM
Iridium Certus 700 <1.0.1 - Info Disclosure
CVE-2025-2394 MEDIUM
Ecovacs Home <3.3.0 - Info Disclosure
CVE-2025-48414 MEDIUM
eCharge Hardy Barth cPH2 / cPP2 charging stations <= 2.2.0 - Use of Hard-coded Credentials
CVSS 6.5
CVE-2025-48413 HIGH
eCharge Hardy Barth cPH2 / cPP2 charging stations <= 2.2.0 - Use of Hard-coded Credentials
CVSS 7.7
CVE-2025-45746 MEDIUM
ZKT ZKBio CVSecurity 6.4.1_R - Auth Bypass
CVSS 6.5
CVE-2025-27488 MEDIUM
Windows Hardware Lab Kit - Privilege Escalation
CVSS 6.7
CVE-2025-47730 MEDIUM
TeleMessage < 2025-05-05 - Use of Hard-coded Credentials
CVSS 4.8
CVE-2025-20188 CRITICAL
Cisco IOS XE - Unauthenticated Arbitrary File Upload and Remote Code Execution via Hard-coded JWT
CVSS 10.0
CVE-2025-4041 CRITICAL
Optigo Networks ONS NC600 <4.7.2.330 - Command Injection
CVE-2025-32889 HIGH
goTenna Mesh Firmware - Use of Hard-coded Credentials for SMS Verification
CVSS 7.3
CVE-2025-32888 HIGH
goTenna Mesh Firmware 1.1.12 - Use of Hard-coded Credentials
CVSS 7.3
CVE-2025-23179 MEDIUM
Ribbon Apollo 9608 v9.6R3 - Hard-Coded Credentials
CVSS 5.5
CVE-2025-32985 CRITICAL
NETSCOUT nGeniusONE < 6.4.0 - Use of Hard-coded Credentials in JAR Files
CVSS 9.8
CVE-2025-46617 HIGH
Quantum StorNext Web GUI API <7.2.4 - Info Disclosure
CVSS 7.2
CVE-2025-46274 CRITICAL
Planet Technology UNI-NMS-Lite < 1.0b211018 - Unauthenticated Use of Hard-coded Credentials
CVSS 9.8
CVE-2025-46273 CRITICAL
UNI-NMS-Lite - Privilege Escalation
CVSS 9.8
CVE-2025-2765 HIGH
CarlinKit CPC200-CCPA - Unauthenticated Authentication Bypass via Hard-Coded Credentials
CVSS 8.8
CVE-2025-28230 CRITICAL
JMBroadcast JMB0150 Firmware v1.0 - Use of Hard-coded Credentials
CVSS 9.1
CVE-2025-3426 HIGH
Intellispace Portal - Info Disclosure
CVE-2025-30406 CRITICAL KEV
Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCE
CVSS 9.0
Details
Vulnerabilities 1,755
Exploit Likelihood High