CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,718 vulnerabilities with CWE-798
CVE-2022-35491 CRITICAL
TOTOLINK A3002RU V3.0.0-B20220304.1804 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-22144 CRITICAL
TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14 - Info Disclosure
CVSS 9.8
CVE-2022-34993 CRITICAL
Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-32965 CRITICAL
OMICARD EDM - Remote Code Execution
CVSS 9.8
CVE-2022-35866 CRITICAL
Vinchin Backup and Recovery 6.5.0.17561 - Auth Bypass
CVSS 9.8
CVE-2022-30314 MEDIUM
Honeywell Experion PKS Safety Manager < r160.1 - Use of Hard-coded Credentials in POLO Bootloader
CVSS 4.6
CVE-2022-36952 HIGH
Veritas NetBackup 8.x-8.3.0.2 9.x-9.0.0.1 9.1.x-9.1.0.1 10 - Use of Hard-coded Credentials in OpsCenter
CVSS 8.4
CVE-2022-30274 CRITICAL
Motorola ACE1000 RTU - Use of Hard-coded Credentials in TEA ECB Encryption
CVSS 9.8
CVE-2022-30271 CRITICAL
Motorola ACE1000 RTU - Info Disclosure
CVSS 9.8
CVE-2022-29964 MEDIUM
Emerson DeltaV Distributed Control System and IO Cards < 2022-04-29 - Use of Hard-coded Credentials
CVSS 5.5
CVE-2022-29963 MEDIUM
Emerson DeltaV Distributed Control System Firmware < 2022-04-29 - Use of Hard-coded Credentials via TELNET
CVSS 5.5
CVE-2022-29962 MEDIUM
Emerson DeltaV Distributed Control System - Use of Hard-coded Credentials
CVSS 5.5
CVE-2022-29960 MEDIUM
Emerson OpenBSI through 2022-04-29 - Use of Hard-coded Credentials via DES Encryption
CVSS 5.5
CVE-2022-29953 CRITICAL
Bently Nevada 3701/40, 3701/44, 3701/46, 60M100 Firmware - Use of Hard-coded Credentials in Maintenance Interface
CVSS 9.8
CVE-2022-34907 CRITICAL
FileWave < 14.6.3 and 14.7.x < 14.7.2 - Unauthenticated Authentication Bypass via Hard-coded Credentials
CVSS 9.8
CVE-2022-34906 HIGH
FileWave < 14.6.3 and 14.7.x < 14.7.2 - Unauthenticated Sensitive Information Exposure via Hard-coded Cryptographic Key
CVSS 7.5
CVE-2022-35287 HIGH
IBM Security Verify Information Queue 10.0.2 - Use of Hard-coded Credentials
CVSS 7.5
CVE-2022-26138 CRITICAL KEV
Atlassian Questions For Confluence - Hardcoded Credentials
CVSS 9.8
CVE-2022-34045 CRITICAL
Wavlink WN530HG4 M30HG4.V5030.191116 - Use of Hard-coded Credentials in Configuration File Encryption
CVSS 9.8
CVE-2022-2107 CRITICAL
MiCODUS MV720 GPS Tracker - Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-24657 CRITICAL
Goldshell ASIC Miners v2.1.x - Auth Bypass
CVSS 9.8
CVE-2022-29060 HIGH
FortiDDoS API <5.5.1 - Code Injection
CVSS 8.1
CVE-2022-30627 MEDIUM
CHCNAV P5E GNSS Firmware - Use of Hard-coded Credentials
CVSS 5.7
CVE-2022-32985 CRITICAL
Nexans FTTO GigaSwitch <6.02N, <7.02 - Privilege Escalation
CVSS 9.8
CVE-2022-31210 CRITICAL
Infiray IRAY-A8Z3 1.0.957 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 1,718
Exploit Likelihood High