The product contains hard-coded credentials, such as a password or cryptographic key.
1,721 vulnerabilities with CWE-798
CVE-2017-18371
CRITICAL
Billion 5200w-t Firmware - Hard-coded Credentials
CVSS 9.8
CVE-2017-9821
CRITICAL
BHIM 1.3 - Authentication Bypass via Hardcoded SMS Validation Strings
CVSS 9.8
CVE-2017-12577
CRITICAL
PLANEX CS-QR20 1.30 - Authenticated Remote Code Execution via Hardcoded Credentials
CVSS 9.8
CVE-2017-12574
CRITICAL
PLANEX CS-W50HD Firmware < 030720 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-13108
HIGH
DFNDR Security Antivirus, Anti-hacking & Cleaner 5.0.9 - Use of Hard-coded Encryption Key
CVSS 7.5
CVE-2017-13107
HIGH
Liveme - Hard-coded Credentials
CVSS 7.5
CVE-2017-13106
HIGH
Cheetahmobile CM Launcher 3D 5.0.3 - Use of Hard-coded Encryption Key
CVSS 7.5
CVE-2017-13104
HIGH
UberEATS 1.108.10001 - Use of Hard-coded Encryption Key
CVSS 7.5
CVE-2017-13102
HIGH
Gameloft Asphalt Xtreme 1.6.0 - Use of Hard-coded Encryption Key
CVSS 7.5
CVE-2017-13101
HIGH
musical.ly 6.1.6 - Use of Hard-coded Encryption Key
CVSS 7.5
CVE-2017-13100
HIGH
The Moron Test 6.3.1 - Use of Hard-coded Encryption Key
CVSS 7.5
CVE-2017-7537
MEDIUM
pki-core <10.6.4 - Auth Bypass
CVSS 5.9
CVE-2017-17540
CRITICAL
Fortinet FortiWLC 7.0-7.0.10 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-17539
CRITICAL
FortiWLC < 7.0.11 - Unauthenticated Remote Shell Access via Hardcoded Account
CVSS 9.8
CVE-2017-14014
MEDIUM
Boston Scientific ZOOM LATITUDE PRM Model 3120 - Info Disclosure
CVSS 4.6
CVE-2017-9656
CRITICAL
Philips DoseWise Portal <2.1.1.3069 - Info Disclosure
CVSS 9.1
CVE-2017-14008
CRITICAL
GE Centricity PACS RA1000 - Auth Bypass
CVSS 9.8
CVE-2017-14006
CRITICAL
GE Xeleris - Improper Authentication via Default or Hard-Coded Credentials
CVSS 9.8
CVE-2017-14004
CRITICAL
GE GEMNet License Server - Auth Bypass
CVSS 9.8
CVE-2017-14002
CRITICAL
GE Infinia/Infinia with Hawkeye 4 - Auth Bypass
CVSS 9.8
CVE-2017-8013
CRITICAL
EMC Data Protection Advisor 6.3.x-6.4.x - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-1787
MEDIUM
IBM Engineering Lifecycle Optimization - Publishing 2.1.2 and 6.0.5 - Use of Hard-coded Credentials
CVSS 4.4
CVE-2017-11634
CRITICAL
Wireless IP Camera 360 - Info Disclosure
CVSS 9.8
CVE-2017-11632
CRITICAL
Wireless IP Camera 360 - Info Disclosure
CVSS 9.8
CVE-2017-12726
HIGH
Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump 1.1, 1.5, 1.6 - Use of Hard-coded Credentials in Telnet
CVSS 7.3
Details
Vulnerabilities
1,721
Exploit Likelihood
High