ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attacke
Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper passwor
9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an ins
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorizati
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder <
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor s
My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.proper
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allow
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. A
An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password
: Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control v
Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configu
Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protec
The administrative credentials can be extracted through application API responses, mobile application reverse engineerin
The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses h
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the exp
UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repea
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not se
go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202
DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from
The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from int
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosqui
FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel'
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows
netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0
A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the compo
A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The affected element is an unknow
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet
IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic k
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credent
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credent
openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation ch
Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end u
The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be u
IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Inte
HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensiti
Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.
NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. P
FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption k
Frequently Asked Questions
What is CWE-798?
CWE-798 (CWE-798) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-798?
There are 681 CVE records associated with CWE-798 in our database. Of these, 297 are critical severity, 182 are high severity, and 76 are medium severity.
How can I protect against CWE-798 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-798 using AI-powered security agents.
Detect CWE-798 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-798 vulnerabilities across your infrastructure.
Get Started