LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.
DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and
Allegra Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass
Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacker
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credenti
Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attack
Weak account password in GE HealthCare EchoPAC products
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryp
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryp
Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows
A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series c
The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This c
An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generati
Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthentica
Multiple MachineSense devices have credentials unable to be changed by the user or administrator.
your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.8.0 use a hardcoded JSO
An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthe
A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By e
There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their
API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote
D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent at
D-Link DAP-2622 Telnet CLI Use of Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows n
D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability allows network-adjacent
Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker co
Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the r
D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attac
Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the har
ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent at
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journ
Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.
Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.
Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowi
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update package
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) w
Azure Stack HCI Elevation of Privilege Vulnerability
Logsign Unified SecOps Platform HTTP API Hard-coded Cryptographic Key Remote Code Execution Vulnerability. This vulnerab
Ever Traduora 0.20.0 and below is vulnerable to Privilege Escalation due to the use of a hard-coded JWT signing key.
Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which a
The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. I
TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allo
Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthor
The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware d
The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple
The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard
A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote u
Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent
Frequently Asked Questions
What is CWE-798?
CWE-798 (CWE-798) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-798?
There are 2,078 CVE records associated with CWE-798 in our database. Of these, 770 are critical severity, 585 are high severity, and 309 are medium severity.
How can I protect against CWE-798 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-798 using AI-powered security agents.
Detect CWE-798 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-798 vulnerabilities across your infrastructure.
Get Started