Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-321

MITRE ↗

CWE-321

24
CRITICAL
23
HIGH
25
MEDIUM
17
LOW
102 CVEs · Page 1/3
9.8
CVE-2025-62581

Delta Electronics DIAView has multiple vulnerabilities.

9.8
CVE-2026-22586

Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Pr

9.8
CVE-2026-25505

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardc

9.8
CVE-2026-22906

User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining

9.8
CVE-2026-25894

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allo

9.8
CVE-2026-26335

Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web app

9.8
CVE-2025-67305

In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These

9.8
CVE-2025-67112

Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (F

9.8
CVE-2026-32644

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

9.8
CVE-2026-28742

Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmwar

9.8
CVE-2026-56271

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refr

9.8
CVE-2026-47410

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an ins

9.8
CVE-2021-32086

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encrypt

9.8
CVE-2026-16504

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database passw

9.8
CVE-2026-74233

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE242

9.1
CVE-2026-5426

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 all

9.1
CVE-2026-31986

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. U

9.1
CVE-2026-50091

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses h

9.1
CVE-2026-62241

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me')

9.1
CVE-2026-54363

CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to fo

9.1
CVE-2026-18753

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatio

9.1
CVE-2026-18754

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatio

9.1
CVE-2026-14804

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Hu

9.1
CVE-2026-51977

An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker t

8.8
CVE-2026-76847

act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact

8.6
CVE-2026-33362

In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps

8.4
CVE-2026-34635

is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low

8.3
CVE-2025-40946

A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.

8.2
CVE-2015-10148

Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical

8.1
CVE-2026-24218

NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes id

8.1
CVE-2026-35019

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows

8.1
CVE-2026-18411

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication k

7.9
CVE-2026-66763

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects usi

7.8
CVE-2026-1442

Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an a

7.8
CVE-2026-6787

Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Pr

7.8
CVE-2026-63423

During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manag

7.7
CVE-2026-32324

Anviz CX7 Firmware is  vulnerable because the application embeds reusable certificate/key material, enabling decryption

7.5
CVE-2026-27519

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded i

7.5
CVE-2026-33266

Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set

7.5
CVE-2026-9220

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and i

7.5
CVE-2026-13184

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKe

7.5
CVE-2025-15627

A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to

7.4
CVE-2026-54833

Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.

7.3
CVE-2025-15605

A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables

7.3
CVE-2026-6580

A security vulnerability has been detected in liangliangyy DjangoBlog up to 2.1.0.0. Affected is an unknown function of

7.3
CVE-2025-55449

AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us

7.1
CVE-2026-2103

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, da

6.8
CVE-2026-57262

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded

6.5
CVE-2026-32958

SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user m

6.5
CVE-2026-25107

ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files

Frequently Asked Questions

What is CWE-321?

CWE-321 (CWE-321) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-321?

There are 102 CVE records associated with CWE-321 in our database. Of these, 24 are critical severity, 23 are high severity, and 25 are medium severity.

How can I protect against CWE-321 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-321 using AI-powered security agents.

Detect CWE-321 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-321 vulnerabilities across your infrastructure.

Get Started