CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,719 vulnerabilities with CWE-798
CVE-2022-31210 CRITICAL
Infiray IRAY-A8Z3 1.0.957 - Info Disclosure
CVSS 9.8
CVE-2022-30622 MEDIUM
CHCNAV P5E GNSS Firmware - Unauthenticated Hard-coded Credential Exposure via Login.js
CVSS 5.3
CVE-2022-32389 HIGH
Isode SWIFT 4.0.2 - Use of Hard-coded Credentials in Registry Editor
CVSS 7.5
CVE-2022-28371 HIGH
Verizon 5G Home LVSKIHP InDoorUnit/ODU <3.4.66.162/<3.33.101.0 - In...
CVSS 7.5
CVE-2022-35857 CRITICAL
kVF Admin <2022-02-12 - Code Injection
CVSS 9.8
CVE-2022-34151 HIGH
Machine automation controller <1.48 - Info Disclosure
CVSS 8.1
CVE-2022-30997 HIGH
STARDOM FCN/FCJ Controller <4.32 - Info Disclosure
CVSS 7.2
CVE-2022-34005 CRITICAL
Titan FTP Server NextGen < 1.2.1050 - Remote Code Execution via Hardcoded SQL sa Password
CVSS 9.8
CVE-2022-30422 CRITICAL
Proietti Planet Time Enterprise - Remote Code Execution via Viewstate Parameter
CVSS 9.8
CVE-2022-31619 HIGH
Teamcenter <V12.4.0.13, <V13.0.0.9, <V13.1.0.9, <V13.2.0.9, <V13.3....
CVSS 8.8
CVE-2022-26476 HIGH
Spectrum Power 4, 7, and MGMS - Unauthenticated Use of Hard-coded Credentials in Shared HIS
CVSS 8.8
CVE-2022-29525 CRITICAL
Rakuten Casa AP_F_V1_4_1 and AP_F_V2_0_0 - Unauthenticated Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-25807 MEDIUM
IGEL Universal Management Suite 6.07.100 - Use of Hard-coded DES Key in LDAPDesPWEncrypter
CVSS 5.5
CVE-2022-25806 HIGH
IGEL Universal Management Suite 6.07.100 - Use of Hard-coded DES Key in PrefDBCredentials
CVSS 8.8
CVE-2022-29778 HIGH
D-Link DIR-890L < 1.22b01 - Remote Code Execution via Hardcoded Wake-On-Lan Descriptor
CVSS 8.8
CVE-2022-30234 CRITICAL
Wiser Smart EER21000 and EER21001 Firmware < 4.5 - Use of Hard-coded Credentials
CVSS 9.4
CVE-2022-31462 CRITICAL
Owl Labs Meeting Owl 5.2.0.15 - Device Control via Backdoor Password
CVSS 9.3
CVE-2022-31460 HIGH
Owl Labs Meeting Owl <5.2.0.15 - Code Injection
CVSS 7.4
CVE-2022-29730 CRITICAL
USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-28605 CRITICAL
Linkplay SDK 1.00 - Privilege Escalation
CVSS 9.8
CVE-2022-29186 CRITICAL
Rundeck <4.0 - Privilege Escalation
CVSS 9.1
CVE-2022-29645 CRITICAL
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 - Hard-coded Credentials in /etc/shadow.sample
CVSS 9.8
CVE-2022-29644 CRITICAL
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 - Use of Hard-coded Credentials in Telnet Service
CVSS 9.8
CVE-2022-1701 HIGH
SonicWall SMA1000 - Info Disclosure
CVSS 7.5
CVE-2022-27172 HIGH
InHand Networks InRouter302 V3.5.37 - Code Injection
CVSS 8.8
Details
Vulnerabilities 1,719
Exploit Likelihood High