Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded c
Qognify NiceVision versions 3.1 and prior are vulnerable to exposing sensitive information using hard-coded credent
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customer
Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can
KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resul
EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user
Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypas
A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet servic
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /e
TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the compon
Western Digital My Cloud devices before OS5 have a nobody account with a blank password.
Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.
Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and e
Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used
A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote
Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker
Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu
Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.
Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.
An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor
Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain a
The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish
Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection st
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UA
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that ca
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmwa
Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over t
Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users lis
PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use t
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.
Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens
Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for devi
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login
The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure
SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An
SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can explo
A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.
i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and
An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive
Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Li
A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected de
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug su
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The
Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.
Frequently Asked Questions
What is CWE-798?
CWE-798 (CWE-798) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-798?
There are 2,078 CVE records associated with CWE-798 in our database. Of these, 770 are critical severity, 585 are high severity, and 309 are medium severity.
How can I protect against CWE-798 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-798 using AI-powered security agents.
Detect CWE-798 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-798 vulnerabilities across your infrastructure.
Get Started