An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained
Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions.
Hard-coded credentials were included as part of the application binary. These credentials served as part of the applica
A vulnerability classified as problematic was found in Audi UTR Dashcam 2.0. Affected by this vulnerability is an unknow
A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects
A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attack
A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the funct
A vulnerability, which was classified as problematic, has been found in mao888 bluebell-plus up to 2.3.0. This issue aff
A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality
A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. Affected by this vulnerability is an unknown fu
A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxu
A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown functio
A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versio
A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionalit
A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the c
A vulnerability was identified in Cudy LT500E up to 2.3.12. Affected is an unknown function of the file /squashfs-root/e
A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro
A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some u
A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an unknown function of the file
A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /et
We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Spe
In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh serve
Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alib
Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a loca
Project AI is a platform designed to create AI agents. Prior to the pre-beta version, a hardcoded API key was present in
A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the
An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with
This vulnerability exists in Digisol DG-GR6821AC Router due to hard-coded Root Access Credentials in system configuratio
Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20
Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allow
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token t
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token t
An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php e
Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vul
onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd
Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain
This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the
This vulnerability exists in ZKTeco WL20 due to hard-coded private key stored in plaintext within the device firmware. A
The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly a
api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower t
Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Rev
An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. Th
Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple
Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains
Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authori
The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Av
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default cred
Root user password is hardcoded into the device and cannot be changed in the user interface.
A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacke
DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.
Frequently Asked Questions
What is CWE-798?
CWE-798 (CWE-798) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-798?
There are 2,078 CVE records associated with CWE-798 in our database. Of these, 770 are critical severity, 585 are high severity, and 309 are medium severity.
How can I protect against CWE-798 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-798 using AI-powered security agents.
Detect CWE-798 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-798 vulnerabilities across your infrastructure.
Get Started