Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate p
Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate pri
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic k
Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user l
Mutiny 7.2.0-10788 suffers from Hardcoded root password.
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root l
The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TI
A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenti
Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial nu
PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicly exposed in main.py,
ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and
Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and M
When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER
Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator pri
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass aut
In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An atta
A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud S
An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4 control software for versio
D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the param
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredenti
A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V1
MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitra
MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product
Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating sy
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the compo
GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with phy
In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsyst
Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5
MegaRAC Default Credentials Vulnerability
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to o
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code e
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the ta
Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earl
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2,
MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion.
A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vul
BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to a
Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network t
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-
A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versi
TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Frequently Asked Questions
What is CWE-798?
CWE-798 (CWE-798) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-798?
There are 2,078 CVE records associated with CWE-798 in our database. Of these, 770 are critical severity, 585 are high severity, and 309 are medium severity.
How can I protect against CWE-798 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-798 using AI-powered security agents.
Detect CWE-798 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-798 vulnerabilities across your infrastructure.
Get Started