Skip to content
Noroxi

CWE-259 · 193 records

Use of Hard-coded Password

CVEs in this class

193 records

  • CVE-2023-5222
    63This week

    Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password

    CriticalCVSS 9.8Proof of conceptEPSS 80%

    viessmann · vitogate 300 firmwareSep 27, 2023

  • CVE-2026-20316
    62This week

    Cisco Secure Firewall Management Center Software Static Credential Vulnerability

    MediumCVSS 5.3KEVWeaponizedEPSS 35%

    cisco · secure firewall management centerJul 29, 2026

  • Sinapsi eSolar Hard-Coded Password

    CriticalCVSS 10.0Proof of conceptEPSS 12%

    sinapsitech · sinapsi firmwareNov 23, 2012

  • TOTOLINK CP450 Telnet Service product.ini hard-coded password

    CriticalCVSS 9.3Proof of conceptEPSS 21%

    totolink · cp450 firmwareJul 31, 2024

  • Morpho Itemiser 3 Hard-Coded Credential

    CriticalCVSS 10.0No exploitEPSS 2%

    morpho · itemiser 3Jul 26, 2014

  • USR USR-G806 Web Management Page hard-coded password

    CriticalCVSS 9.8No exploitEPSS 3%

    usr · usr-g806 firmwareMay 11, 2023

  • A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A32

    CriticalCVSS 9.8No exploitEPSS 2%

    marel · a320 firmwareJun 29, 2017

  • Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and

    CriticalCVSS 9.8No exploitEPSS 2%

    pifzer · plum a\+ infusion system firmwareMar 25, 2019

  • Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5,

    CriticalCVSS 9.8No exploitEPSS 2%

    baxter · em2400 firmwareJun 29, 2020

  • A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink P

    CriticalCVSS 9.8No exploitEPSS 2%

    schneider-electric · evlink city evc1s22p4 firmwareJul 21, 2021

  • A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Jour

    CriticalCVSS 9.8No exploitEPSS 2%

    bd · performaJun 29, 2017

  • The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-defa

    CriticalCVSS 9.8No exploitEPSS 2%

    baxter · sigma spectrum infusion system firmwareJun 29, 2020

  • The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), op

    CriticalCVSS 9.8No exploitEPSS 2%

    baxter · sigma spectrum infusion system firmwareJun 29, 2020

  • A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).

    CriticalCVSS 10.0No exploitEPSS 1%

    siemens · simatic cn 4100 firmwareMay 14, 2024

  • CVE-2014-5434
    39Monitor

    Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with

    CriticalCVSS 9.8No exploitEPSS 2%

    baxter · sigma spectrum infusion system firmwareMar 26, 2019

  • The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components

    CriticalCVSS 9.8No exploitEPSS 1%

    ge · reason dr60 firmwareMar 25, 2021

  • SICUNET Access Controller hard-coded password

    CriticalCVSS 9.8No exploitEPSS 1%

    sicunet · access controlJun 11, 2022

  • Moxa MXview Network Management Software

    CriticalCVSS 9.8No exploitEPSS 1%

    moxa · mxviewOct 12, 2021

  • ISE on AWS Static Credential

    CriticalCVSS 9.8No exploitEPSS 1%

    cisco · identity services engineJun 4, 2025

  • Bender Charge Controller: Hardcoded Credentials in Charge Controller

    CriticalCVSS 9.8No exploitEPSS 1%

    bender · cc612 firmwareApr 27, 2022

  • A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623.

    CriticalCVSS 9.8No exploitEPSS 1%

    level1 · wbr-6013 firmwareJul 8, 2024

  • Default hidden Privileged Account Vulnerability in multiple XEROX devices

    CriticalCVSS 9.8No exploitEPSS 1%

    xerox · altalink b8045 firmwareApr 13, 2021

  • A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_0

    CriticalCVSS 9.8No exploitEPSS 1%

    tcl · linkhub mesh wifi ac1200Aug 5, 2022

  • Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select use

    CriticalCVSS 9.8No exploitEPSS 1%

    sewio · real-time location system studioJan 17, 2023

  • CVE-2023-3237
    39Monitor

    OTCMS hard-coded password

    CriticalCVSS 9.8No exploitEPSS 1%

    otcms · otcmsJun 14, 2023

All vulnerability classes