CWE-259 · 193 records
Use of Hard-coded Password
CVEs in this class
193 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
63This week | CVE-2023-5222Proof of concept | Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded passwordviessmann · vitogate 300 firmware · CWE-259 | Critical9.8 | — | 80.4% | Sep 27, 2023 |
62This week | CVE-2026-20316Weaponized | Cisco Secure Firewall Management Center Software Static Credential Vulnerabilitycisco · secure firewall management center · CWE-259 | Medium5.3 | KEV | 35.1% | Jul 29, 2026 |
44Plan | CVE-2012-5862Proof of concept | Sinapsi eSolar Hard-Coded Passwordsinapsitech · sinapsi firmware · CWE-259 | Critical10.0 | — | 12.1% | Nov 23, 2012 |
43Plan | CVE-2024-7332Proof of concept | TOTOLINK CP450 Telnet Service product.ini hard-coded passwordtotolink · cp450 firmware · CWE-259 | Critical9.3 | — | 20.7% | Jul 31, 2024 |
41Plan | CVE-2014-2363No exploit | Morpho Itemiser 3 Hard-Coded Credentialmorpho · itemiser 3 · CWE-259 | Critical10.0 | — | 2.1% | Jul 26, 2014 |
40Plan | CVE-2023-2645No exploit | USR USR-G806 Web Management Page hard-coded passwordusr · usr-g806 firmware · CWE-259 | Critical9.8 | — | 3.2% | May 11, 2023 |
40Plan | CVE-2016-9358No exploit | A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A32marel · a320 firmware · CWE-259 | Critical9.8 | — | 2.1% | Jun 29, 2017 |
40Plan | CVE-2015-3953No exploit | Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and pifzer · plum a\+ infusion system firmware · CWE-259 | Critical9.8 | — | 2.0% | Mar 25, 2019 |
40Plan | CVE-2020-12016No exploit | Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5,baxter · em2400 firmware · CWE-259 | Critical9.8 | — | 1.9% | Jun 29, 2020 |
40Plan | CVE-2021-22729No exploit | A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Pschneider-electric · evlink city evc1s22p4 firmware · CWE-259 | Critical9.8 | — | 1.8% | Jul 21, 2021 |
40Plan | CVE-2017-6022No exploit | A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Jourbd · performa · CWE-259 | Critical9.8 | — | 1.8% | Jun 29, 2017 |
40Plan | CVE-2020-12047No exploit | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-defabaxter · sigma spectrum infusion system firmware · CWE-259 | Critical9.8 | — | 1.7% | Jun 29, 2020 |
40Plan | CVE-2020-12045No exploit | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), opbaxter · sigma spectrum infusion system firmware · CWE-259 | Critical9.8 | — | 1.7% | Jun 29, 2020 |
40Plan | CVE-2024-32741No exploit | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).siemens · simatic cn 4100 firmware · CWE-259 | Critical10.0 | — | 0.6% | May 14, 2024 |
39Monitor | CVE-2014-5434No exploit | Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account withbaxter · sigma spectrum infusion system firmware · CWE-259 | Critical9.8 | — | 1.6% | Mar 26, 2019 |
39Monitor | CVE-2021-27440No exploit | The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components ge · reason dr60 firmware · CWE-259 | Critical9.8 | — | 1.4% | Mar 25, 2021 |
39Monitor | CVE-2017-20039No exploit | SICUNET Access Controller hard-coded passwordsicunet · access control · CWE-259 | Critical9.8 | — | 1.2% | Jun 11, 2022 |
39Monitor | CVE-2021-38456No exploit | Moxa MXview Network Management Softwaremoxa · mxview · CWE-259 | Critical9.8 | — | 1.2% | Oct 12, 2021 |
39Monitor | CVE-2025-20286No exploit | ISE on AWS Static Credentialcisco · identity services engine · CWE-259 | Critical9.8 | — | 1.1% | Jun 4, 2025 |
39Monitor | CVE-2021-34601No exploit | Bender Charge Controller: Hardcoded Credentials in Charge Controllerbender · cc612 firmware · CWE-259 | Critical9.8 | — | 1.1% | Apr 27, 2022 |
39Monitor | CVE-2023-46685No exploit | A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623.level1 · wbr-6013 firmware · CWE-259 | Critical9.8 | — | 1.0% | Jul 8, 2024 |
39Monitor | CVE-2019-10881No exploit | Default hidden Privileged Account Vulnerability in multiple XEROX devicesxerox · altalink b8045 firmware · CWE-259 | Critical9.8 | — | 1.0% | Apr 13, 2021 |
39Monitor | CVE-2022-22144No exploit | A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_0tcl · linkhub mesh wifi ac1200 · CWE-259 | Critical9.8 | — | 1.0% | Aug 5, 2022 |
39Monitor | CVE-2022-45444No exploit | Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select usesewio · real-time location system studio · CWE-259 | Critical9.8 | — | 0.9% | Jan 17, 2023 |
39Monitor | CVE-2023-3237No exploit | OTCMS hard-coded passwordotcms · otcms · CWE-259 | Critical9.8 | — | 0.9% | Jun 14, 2023 |
- CVE-2023-522263This week
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
CriticalCVSS 9.8Proof of conceptEPSS 80%viessmann · vitogate 300 firmwareSep 27, 2023
- CVE-2026-2031662This week
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
MediumCVSS 5.3KEVWeaponizedEPSS 35%cisco · secure firewall management centerJul 29, 2026
- CVE-2012-586244Plan
Sinapsi eSolar Hard-Coded Password
CriticalCVSS 10.0Proof of conceptEPSS 12%sinapsitech · sinapsi firmwareNov 23, 2012
- CVE-2024-733243Plan
TOTOLINK CP450 Telnet Service product.ini hard-coded password
CriticalCVSS 9.3Proof of conceptEPSS 21%totolink · cp450 firmwareJul 31, 2024
- CVE-2014-236341Plan
Morpho Itemiser 3 Hard-Coded Credential
CriticalCVSS 10.0No exploitEPSS 2%morpho · itemiser 3Jul 26, 2014
- CVE-2023-264540Plan
USR USR-G806 Web Management Page hard-coded password
CriticalCVSS 9.8No exploitEPSS 3%usr · usr-g806 firmwareMay 11, 2023
- CVE-2016-935840Plan
A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A32
CriticalCVSS 9.8No exploitEPSS 2%marel · a320 firmwareJun 29, 2017
- CVE-2015-395340Plan
Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and
CriticalCVSS 9.8No exploitEPSS 2%pifzer · plum a\+ infusion system firmwareMar 25, 2019
- CVE-2020-1201640Plan
Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5,
CriticalCVSS 9.8No exploitEPSS 2%baxter · em2400 firmwareJun 29, 2020
- CVE-2021-2272940Plan
A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink P
CriticalCVSS 9.8No exploitEPSS 2%schneider-electric · evlink city evc1s22p4 firmwareJul 21, 2021
- CVE-2017-602240Plan
A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Jour
CriticalCVSS 9.8No exploitEPSS 2%bd · performaJun 29, 2017
- CVE-2020-1204740Plan
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-defa
CriticalCVSS 9.8No exploitEPSS 2%baxter · sigma spectrum infusion system firmwareJun 29, 2020
- CVE-2020-1204540Plan
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), op
CriticalCVSS 9.8No exploitEPSS 2%baxter · sigma spectrum infusion system firmwareJun 29, 2020
- CVE-2024-3274140Plan
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).
CriticalCVSS 10.0No exploitEPSS 1%siemens · simatic cn 4100 firmwareMay 14, 2024
- CVE-2014-543439Monitor
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with
CriticalCVSS 9.8No exploitEPSS 2%baxter · sigma spectrum infusion system firmwareMar 26, 2019
- CVE-2021-2744039Monitor
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components
CriticalCVSS 9.8No exploitEPSS 1%ge · reason dr60 firmwareMar 25, 2021
- CVE-2017-2003939Monitor
SICUNET Access Controller hard-coded password
CriticalCVSS 9.8No exploitEPSS 1%sicunet · access controlJun 11, 2022
- CVE-2021-3845639Monitor
Moxa MXview Network Management Software
CriticalCVSS 9.8No exploitEPSS 1%moxa · mxviewOct 12, 2021
- CVE-2025-2028639Monitor
ISE on AWS Static Credential
CriticalCVSS 9.8No exploitEPSS 1%cisco · identity services engineJun 4, 2025
- CVE-2021-3460139Monitor
Bender Charge Controller: Hardcoded Credentials in Charge Controller
CriticalCVSS 9.8No exploitEPSS 1%bender · cc612 firmwareApr 27, 2022
- CVE-2023-4668539Monitor
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623.
CriticalCVSS 9.8No exploitEPSS 1%level1 · wbr-6013 firmwareJul 8, 2024
- CVE-2019-1088139Monitor
Default hidden Privileged Account Vulnerability in multiple XEROX devices
CriticalCVSS 9.8No exploitEPSS 1%xerox · altalink b8045 firmwareApr 13, 2021
- CVE-2022-2214439Monitor
A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_0
CriticalCVSS 9.8No exploitEPSS 1%tcl · linkhub mesh wifi ac1200Aug 5, 2022
- CVE-2022-4544439Monitor
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select use
CriticalCVSS 9.8No exploitEPSS 1%sewio · real-time location system studioJan 17, 2023
- CVE-2023-323739Monitor
OTCMS hard-coded password
CriticalCVSS 9.8No exploitEPSS 1%otcms · otcmsJun 14, 2023