CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,721 vulnerabilities with CWE-798
CVE-2020-12376 MEDIUM
Intel BMC Firmware < 2.47 - Authenticated Information Disclosure via Hard-coded Key
CVSS 5.5
CVE-2020-35567 HIGH
MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 < 2.6.2 - Use of Hard-coded Database Credentials
CVSS 7.8
CVE-2020-25493 HIGH
Oclean Mobile Application 2.1.2 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-15833 CRITICAL
Mofi Network MOFI4500-4GXeLTE 4.1.5-std - Use of Hard-coded Credentials for Root SSH Access
CVSS 9.8
CVE-2020-13858 CRITICAL
Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std - Use of Hard-coded Credentials
CVSS 9.8
CVE-2020-6779 CRITICAL
Bosch FSM-2500 and FSM-5000 Firmware <= 5.2 - Unauthenticated Use of Hard-coded Credentials
CVSS 10.0
CVE-2020-28999 HIGH
Geeni GNC-CW013 Firmware 1.8.1 - Use of Hard-coded Credentials
CVSS 7.2
CVE-2020-28998 CRITICAL
Geeni GNC-CW013 Firmware 1.8.1 - Use of Hard-coded Credentials in Telnet Service
CVSS 9.8
CVE-2020-25173 HIGH
Reolink P2P Cameras - Fixed Cryptography Key Disclosure
CVSS 7.8
CVE-2020-4983 HIGH
IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 - Authenticated Remote Code Execution via Job Submission
CVSS 7.8
CVE-2020-27256 MEDIUM
SOOIL Developments Co., Ltd - Info Disclosure
CVSS 6.8
CVE-2020-35929 CRITICAL
Kaspersky TinyCheck < 2020-12-18 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2020-28395 MEDIUM
SCALANCE X-200RNA/X-300 - Info Disclosure
CVSS 5.9
CVE-2020-28391 MEDIUM
SCALANCE X-200 and X-200IRT Firmware < 5.5.0 - Use of Hard-coded Cryptographic Key via C-PLUG
CVSS 5.9
CVE-2020-10206 MEDIUM
Amino AK45x AK5xx AK65x Aria6xx Aria7xx Kami7B Firmware - Hard-coded VNC Password
CVSS 4.4
CVE-2020-10210 CRITICAL
Amino AK45x AK5xx AK65x Aria6xx Aria7xx Kami7B Firmware - Use of Hard-coded SSH Credentials
CVSS 9.8
CVE-2020-10207 CRITICAL
Amino AK45x AK5xx AK65x Aria6xx Aria7xx Kami7B Firmware - Use of Hard-coded Credentials in EntoneWebEngine
CVSS 9.8
CVE-2020-29193 MEDIUM
Panasonic Security System WV-S2231L 4.25 - Info Disclosure
CVSS 6.8
CVE-2020-2499 MEDIUM
QES < 2.1.1 - Unauthenticated Hard-Coded Password Bypass
CVSS 6.3
CVE-2020-11719 HIGH
bilanc < 014_31.01.2020 - Use of Hard-coded Credentials via Weak Static Encryption Key
CVSS 7.5
CVE-2020-11720 CRITICAL
bilanc < 014_31.01.2020 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2020-8995 CRITICAL
bilanc < 014_31.01.2020 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2020-6882 HIGH
ZTE ZXHN E8810/E8820/E8822 Firmware - Information Disclosure via Hard-coded MQTT Credentials
CVSS 7.5
CVE-2020-25620 HIGH
SolarWinds N-Central 12.3.0.670 - Use of Hard-coded Credentials
CVSS 7.8
CVE-2020-0016 HIGH
Broadcom Nexus - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 1,721
Exploit Likelihood High