CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,721 vulnerabilities with CWE-798
CVE-2017-8771 CRITICAL
BE126 WIFI Repeater 1.0 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-14143 CRITICAL
Kaltura Server < mercury-13.1.0 - Remote Code Execution via Hardcoded Cookie Secret
CVSS 9.8
CVE-2017-14428 HIGH
D-Link DIR-850L - Privilege Escalation
CVSS 7.8
CVE-2017-14426 HIGH
D-Link DIR-850L REV. A FW114WWb07 & REV. B FW208WWb02 - Hard-coded Credentials Exposure via Shadow File
CVSS 7.8
CVE-2017-14422 HIGH
D-Link DIR-850L REV. A and B - Hard-coded Private Key in stunnel
CVSS 7.5
CVE-2017-14421 CRITICAL
D-Link DIR-850L REV. B - Info Disclosure
CVSS 9.8
CVE-2017-11351 CRITICAL
Axesstel MU553S MU55XS-V1.14 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-14116 HIGH
AT&T U-verse <9.2.2h0d83 - Privilege Escalation
CVSS 8.1
CVE-2017-14115 HIGH
AT&T U-verse 9.2.2h0d83 - Code Injection
CVSS 8.1
CVE-2017-12709 MEDIUM
Westermo MRD-305-DIN, MRD-315, MRD-355, and MRD-455 < 1.7.5.0 - Use of Hard-coded Credentials
CVSS 5.3
CVE-2017-9852 CRITICAL
SMA Solar Technology - Info Disclosure
CVSS 9.8
CVE-2017-10818 CRITICAL
MaLion 3.2.1-5.2.1 - Use of Hard-coded Cryptographic Key
CVSS 9.8
CVE-2017-2283 HIGH
I-O DATA WN-G300R3 Firmware <= 1.0.2 - Use of Hard-coded Credentials
CVSS 8.0
CVE-2017-2280 HIGH
I-O DATA WN-AX1167GR <= firmware 3.00 - Use of Hard-coded Credentials
CVSS 8.8
CVE-2017-11380 CRITICAL
Trend Micro Deep Discovery Director 1.1 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-11129 CRITICAL
heinekingmedia StashCat < 1.7.5 - Use of Hard-coded Credentials in Keystore
CVSS 9.8
CVE-2017-11743 CRITICAL
MEDHOST Connex - Use of Hard-coded Credentials in Mirth Connect Admin Account
CVSS 9.8
CVE-2017-9488 HIGH
Cisco DPC3939 and DPC3941T Firmware - Unauthenticated Remote Access via Hardcoded Credentials
CVSS 8.8
CVE-2017-11694 CRITICAL
MEDHOST Document Management System - Info Disclosure
CVSS 9.1
CVE-2017-11693 CRITICAL
MEDHOST Document Management System - Info Disclosure
CVSS 9.1
CVE-2017-11614 CRITICAL
MEDHOST Connex - Use of Hard-coded Credentials in IBM i DB2 User Account
CVSS 9.8
CVE-2017-7336 CRITICAL
Fortinet FortiWLM <8.3.0 - Command Injection
CVSS 9.8
CVE-2017-3222 CRITICAL
Inmarsat AmosConnect 8 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-9932 CRITICAL
Green Packet DX-350 Firmware v2.8.9.5-g1.4.8-atheeb - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-11436 CRITICAL
D-Link DIR-615 < 20.12PTb04 - Use of Hard-coded Credentials via TELNET Backdoor
CVSS 9.8
Details
Vulnerabilities 1,721
Exploit Likelihood High