CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,755 vulnerabilities with CWE-798
CVE-2023-6198 CRITICAL
Baicells Snap Router - Info Disclosure
CVSS 9.3
CVE-2023-49224 HIGH
Precor touchscreen console - Privilege Escalation
CVSS 8.0
CVE-2023-49223 HIGH
Precor Touchscreen Console - Info Disclosure
CVSS 8.8
CVE-2023-49222 HIGH
Precor touchscreen console P82 - Privilege Escalation
CVSS 8.8
CVE-2023-49221 HIGH
Precor touchscreen console - Auth Bypass
CVSS 7.8
CVE-2023-26566 HIGH
Sangoma FreePBX 1805-2203 - Use of Hard-coded Credentials in Asterisk REST Interface
CVSS 8.6
CVE-2023-51629 HIGH
D-Link DCS-8300LHV2 Firmware < 1.07.02 - Unauthenticated Authentication Bypass via ONVIF Hardcoded PIN
CVSS 8.8
CVE-2023-51588 HIGH
Voltronic Power ViewPower Pro - Privilege Escalation
CVSS 7.8
CVE-2023-44411 CRITICAL
D-Link D-View 8 - Unauthenticated Authentication Bypass via Hard-coded Credentials
CVSS 9.8
CVE-2023-39482 MEDIUM
Softing Secure Integration Server < 1.30 - Authenticated Information Disclosure via Hardcoded Cryptographic Key
CVSS 6.5
CVE-2023-39458 MEDIUM
Triangle MicroWorks SCADA Data Gateway - Authentication Bypass via Hard-coded SSL Certificate
CVSS 5.3
CVE-2023-35724 HIGH
D-Link DAP-2622 Firmware < 1.10b03r022 - Unauthenticated Authentication Bypass via Hardcoded Telnet Credentials
CVSS 8.8
CVE-2023-34284 MEDIUM
NETGEAR RAX30 Firmware < 1.0.10.94 - Unauthenticated Authentication Bypass via Hard-coded Credentials
CVSS 6.3
CVE-2023-32145 HIGH
D-Link DAP-1360 and DAP-2020 Firmware - Unauthenticated Authentication Bypass via Hardcoded Credentials
CVSS 8.8
CVE-2023-52723 HIGH
KDE libksieve <23.03.80 - Info Disclosure
CVSS 7.1
CVE-2023-40146 MEDIUM
Peplink Smart Reader Firmware 1.2.0 - Privilege Escalation via /bin/login Hard-coded Credentials
CVSS 6.8
CVE-2023-38535 MEDIUM
OpenText Exceed Turbo X <12.5.2 - Code Injection
CVSS 4.7
CVE-2023-5456 HIGH
AiLux imx6 < 1.0.7-2 - Unauthenticated MariaDB Access via Hard-coded Credentials
CVSS 8.1
CVE-2023-6255 HIGH
Utarit SoliPay <5.0.8 - Info Disclosure
CVSS 7.5
CVE-2023-4539 HIGH
Comarch ERP XL <2023.2 - Info Disclosure
CVSS 7.5
CVE-2023-6409 HIGH
EcoStruxure Control Expert - Info Disclosure
CVSS 7.7
CVE-2023-38995 CRITICAL
SCHUHFRIED v.8.22.00 - Info Disclosure
CVSS 9.8
CVE-2023-46706 CRITICAL
MachineSense Devices - Info Disclosure
CVSS 9.1
CVE-2023-51840 CRITICAL
DoraCMS 2.1.8 - Use of Hard-coded Cryptographic Key
CVSS 9.8
CVE-2023-6482 MEDIUM
Synaptics Fingerprint Driver - Info Disclosure
CVSS 5.2
Details
Vulnerabilities 1,755
Exploit Likelihood High