CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,719 vulnerabilities with CWE-798
CVE-2021-40597 CRITICAL
EDIMAX IC-3140W <3.11 - Info Disclosure
CVSS 9.8
CVE-2021-40903 CRITICAL
antminer_monitor 0.50.0 - Use of Hard-coded Credentials in Flask Settings File
CVSS 9.8
CVE-2021-42892 MEDIUM
TOTOLINK EX1200T V4.1.2cu.5215 - Unauthenticated Telnet Access via Hard-coded Credentials
CVSS 4.3
CVE-2021-33016 CRITICAL
KUKA KR C4 <8.7 - Privilege Escalation
CVSS 9.8
CVE-2021-33014 HIGH
KUKA KR C4 <8.7 - Privilege Escalation
CVSS 8.8
CVE-2021-42850 HIGH
Lenovo Personal Cloud Storage A1/T1/X1/T2/T2Pro Firmware - Use of Hard-coded Credentials
CVSS 8.8
CVE-2021-42849 MEDIUM
Lenovo A1 Firmware < 5.3.6.a1 - Authentication Bypass
CVSS 6.8
CVE-2021-38969 CRITICAL
IBM Spectrum Virtualize <8.5 - Privilege Escalation
CVSS 9.8
CVE-2021-34601 CRITICAL
Bender CC612 Firmware <= 5.20.1 - Hardcoded SSH Credentials
CVSS 9.8
CVE-2021-45841 HIGH
Terramaster F4-210, F2-210 TOS 4.2.X - Info Disclosure
CVSS 8.1
CVE-2021-40422 CRITICAL
Swift Sensors Gateway SG3-1010 - RCE
CVSS 10.0
CVE-2021-40390 CRITICAL
Moxa MXView Series 3.2.4 - Auth Bypass
CVSS 9.8
CVE-2021-30064 CRITICAL
Schneider Electric ConneXium - Auth Bypass
CVSS 9.8
CVE-2021-46008 HIGH
Totolink a3100r V5.9c.4577 - Info Disclosure
CVSS 8.8
CVE-2021-27430 HIGH
GE UR Bootloader <7.03 - Info Disclosure
CVSS 8.4
CVE-2021-45877 CRITICAL
GARO Wallbox GLB/GTB/GTC Firmware < 185 - Use of Hard-coded Credentials in Tomcat Configuration
CVSS 9.8
CVE-2021-41848 HIGH
Bluproducts G90 Firmware - Hard-coded Credentials
CVSS 7.8
CVE-2021-27797 CRITICAL
Brocade Fabric OS <v8.2.1c,v8.1.2h,v8.0.x,v7.x - Info Disclosure
CVSS 9.8
CVE-2021-46247 HIGH
ASUS CMAX6000 <1.02.00 - Info Disclosure
CVSS 7.5
CVE-2021-45106 MEDIUM
SICAM TOOLBOX II - Use of Hard-coded Credentials
CVSS 6.5
CVE-2021-42833 CRITICAL
AquaView 1.60, 7.x, 8.x - Authenticated Use of Hard-coded Credentials
CVSS 9.3
CVE-2021-42635 HIGH
PrinterLogic Web Stack <= 19.1.1.13 SP9 - Unauthenticated Remote Code Execution via Hardcoded APP_KEY
CVSS 8.1
CVE-2021-44464 MEDIUM
Fresenius-kabi Agilia Connect Firmware < d25 - Hard-coded Credentials
CVSS 6.3
CVE-2021-23233 HIGH
Fresenius Kabi Agilia Link+ <3.0 - Info Disclosure
CVSS 7.3
CVE-2021-23842 MEDIUM
Bosch AMC2 Firmware - Use of Hard-coded Cryptographic Key
CVSS 5.7
Details
Vulnerabilities 1,719
Exploit Likelihood High