TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may
D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote a
An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command.
A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3),
INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by
An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA
Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects K
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320
D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability a
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented
Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other servic
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/pr
MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be r
TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, whic
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the databas
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the databas
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the databas
An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability
TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed thro
luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.
Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauth
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_1
An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privilege
Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.
Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all pron
D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attacker
In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers
A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an u
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacker
H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attack
A vulnerability classified as critical has been found in TOTOLINK T10 AC1200 4.1.8cu.5207. Affected is an unknown functi
The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowled
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an a
Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Withi
Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenti
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enable
Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.
IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61,
Frequently Asked Questions
What is CWE-798?
CWE-798 (CWE-798) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-798?
There are 2,078 CVE records associated with CWE-798 in our database. Of these, 770 are critical severity, 585 are high severity, and 309 are medium severity.
How can I protect against CWE-798 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-798 using AI-powered security agents.
Detect CWE-798 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-798 vulnerabilities across your infrastructure.
Get Started