CWE-321 · 319 records
Use of Hard-coded Cryptographic Key
CVEs in this class
320 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
97Now | CVE-2025-30406Weaponized | Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal'gladinet · centrestack · CWE-321 | Critical9.8 | KEV | 94.3% | Apr 3, 2025 |
97Now | CVE-2016-4437Weaponized | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitapache · aurora · CWE-321 | Critical9.8 | KEV | 93.0% | Jun 7, 2016 |
56Plan | CVE-2023-32169No exploit | D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerabilitydlink · d-view 8 · CWE-321 | Critical9.8 | — | 56.1% | May 2, 2024 |
49Plan | CVE-2023-27584Proof of concept | Dragonfly2 vulnerable to hard coded cyptographic keylinuxfoundation · dragonfly · CWE-321 | Critical9.8 | — | 33.9% | Sep 19, 2024 |
42Plan | CVE-2020-10884Weaponized | This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190tp-link · ac1750 firmware · CWE-321 | High8.8 | — | 21.9% | Mar 25, 2020 |
40Plan | CVE-2020-6990No exploit | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versionsrockwellautomation · micrologix 1400 a firmware · CWE-321 | Critical9.8 | — | 4.4% | Mar 16, 2020 |
40Plan | CVE-2021-40119No exploit | Cisco Policy Suite Static SSH Keys Vulnerabilitycisco · policy suite · CWE-321 | Critical9.8 | — | 2.5% | Nov 4, 2021 |
40Plan | CVE-2025-57174Proof of concept | An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previoCWE-321 | Critical9.8 | — | 2.2% | Sep 15, 2025 |
40Plan | CVE-2017-14021No exploit | A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-korenix · jetnet5018g firmware · CWE-321 | Critical9.8 | — | 1.9% | Oct 31, 2017 |
40Plan | CVE-2022-0664No exploit | Use of Hard-coded Cryptographic Key in gravitl/netmakernetmaker · netmaker · CWE-321 | Critical9.8 | — | 1.7% | Feb 18, 2022 |
40Plan | CVE-2022-24860No exploit | Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability.databasir project · databasir · CWE-321 | Critical9.8 | — | 1.7% | Apr 19, 2022 |
40Plan | CVE-2016-9335No exploit | A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Versionredlion · sixnet-managed industrial switches firmware · CWE-321 | Critical10.0 | — | 1.6% | May 9, 2018 |
40Plan | CVE-2026-86708No exploit | Sensitive data exposurezohocorp · manageengine applications manager · CWE-321 | Critical10.0 | — | 1.2% | Sep 23, 2026 |
40Plan | CVE-2024-30207No exploit | A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Managesiemens · simatic rtls locating manager · CWE-321 | Critical10.0 | — | 0.8% | May 14, 2024 |
40Plan | CVE-2025-34217No exploit | Vasion Print (formerly PrinterLogic) Undocumented Hardcoded SSH Keyvasion · virtual appliance application · CWE-321 | Critical10.0 | — | 0.7% | Sep 30, 2025 |
40Plan | CVE-2025-34256No exploit | Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypassadvantech · wise-deviceon server · CWE-321 | Critical10.0 | — | 0.7% | Dec 5, 2025 |
40Plan | CVE-2025-12599No exploit | Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000)azure-access · blu-ic2 firmware · CWE-321 | Critical10.0 | — | 0.4% | Nov 1, 2025 |
39Monitor | CVE-2018-0040No exploit | Contrail Service Orchestration: hardcoded cryptographic certificates and keysjuniper · contrail service orchestration · CWE-321 | Critical9.8 | — | 1.4% | Jul 11, 2018 |
39Monitor | CVE-2022-22987No exploit | The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server logiadvantech · adam-3600 firmware · CWE-321 | Critical9.8 | — | 1.2% | Feb 4, 2022 |
39Monitor | CVE-2022-29186No exploit | Use of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterprisepagerduty · rundeck · CWE-321 | Critical9.8 | — | 1.2% | May 20, 2022 |
39Monitor | CVE-2019-19750No exploit | minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.minerstat · msos · CWE-321 | Critical9.8 | — | 1.1% | Dec 12, 2019 |
39Monitor | CVE-2024-5296No exploit | D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerabilitydlink · d-view 8 · CWE-321 | Critical9.8 | — | 1.1% | May 23, 2024 |
39Monitor | CVE-2021-27389No exploit | A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30).siemens · opcenter quality · CWE-321 | Critical9.8 | — | 1.0% | Apr 22, 2021 |
39Monitor | CVE-2021-32520No exploit | QSAN Storage Manager - Use of Hard-coded Cryptographic Keyqsan · storage manager · CWE-321 | Critical9.8 | — | 1.0% | Jul 7, 2021 |
39Monitor | CVE-2023-37936No exploit | A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 througfortinet · fortiswitch · CWE-321 | Critical9.8 | — | 1.0% | Jan 14, 2025 |
- CVE-2025-3040697Now
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal'
CriticalCVSS 9.8KEVWeaponizedEPSS 94%gladinet · centrestackApr 3, 2025
- CVE-2016-443797Now
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbit
CriticalCVSS 9.8KEVWeaponizedEPSS 93%apache · auroraJun 7, 2016
- CVE-2023-3216956Plan
D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability
CriticalCVSS 9.8No exploitEPSS 56%dlink · d-view 8May 2, 2024
- CVE-2023-2758449Plan
Dragonfly2 vulnerable to hard coded cyptographic key
CriticalCVSS 9.8Proof of conceptEPSS 34%linuxfoundation · dragonflySep 19, 2024
- CVE-2020-1088442Plan
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190
HighCVSS 8.8WeaponizedEPSS 22%tp-link · ac1750 firmwareMar 25, 2020
- CVE-2020-699040Plan
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions
CriticalCVSS 9.8No exploitEPSS 4%rockwellautomation · micrologix 1400 a firmwareMar 16, 2020
- CVE-2021-4011940Plan
Cisco Policy Suite Static SSH Keys Vulnerability
CriticalCVSS 9.8No exploitEPSS 2%cisco · policy suiteNov 4, 2021
- CVE-2025-5717440Plan
An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previo
CriticalCVSS 9.8Proof of conceptEPSS 2%Sep 15, 2025
- CVE-2017-1402140Plan
A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-
CriticalCVSS 9.8No exploitEPSS 2%korenix · jetnet5018g firmwareOct 31, 2017
- CVE-2022-066440Plan
Use of Hard-coded Cryptographic Key in gravitl/netmaker
CriticalCVSS 9.8No exploitEPSS 2%netmaker · netmakerFeb 18, 2022
- CVE-2022-2486040Plan
Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability.
CriticalCVSS 9.8No exploitEPSS 2%databasir project · databasirApr 19, 2022
- CVE-2016-933540Plan
A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version
CriticalCVSS 10.0No exploitEPSS 2%redlion · sixnet-managed industrial switches firmwareMay 9, 2018
- CVE-2026-8670840Plan
Sensitive data exposure
CriticalCVSS 10.0No exploitEPSS 1%zohocorp · manageengine applications managerSep 23, 2026
- CVE-2024-3020740Plan
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manage
CriticalCVSS 10.0No exploitEPSS 1%siemens · simatic rtls locating managerMay 14, 2024
- CVE-2025-3421740Plan
Vasion Print (formerly PrinterLogic) Undocumented Hardcoded SSH Key
CriticalCVSS 10.0No exploitEPSS 1%vasion · virtual appliance applicationSep 30, 2025
- CVE-2025-3425640Plan
Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass
CriticalCVSS 10.0No exploitEPSS 1%advantech · wise-deviceon serverDec 5, 2025
- CVE-2025-1259940Plan
Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000)
CriticalCVSS 10.0No exploitEPSS 0%azure-access · blu-ic2 firmwareNov 1, 2025
- CVE-2018-004039Monitor
Contrail Service Orchestration: hardcoded cryptographic certificates and keys
CriticalCVSS 9.8No exploitEPSS 1%juniper · contrail service orchestrationJul 11, 2018
- CVE-2022-2298739Monitor
The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server logi
CriticalCVSS 9.8No exploitEPSS 1%advantech · adam-3600 firmwareFeb 4, 2022
- CVE-2022-2918639Monitor
Use of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterprise
CriticalCVSS 9.8No exploitEPSS 1%pagerduty · rundeckMay 20, 2022
- CVE-2019-1975039Monitor
minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.
CriticalCVSS 9.8No exploitEPSS 1%minerstat · msosDec 12, 2019
- CVE-2024-529639Monitor
D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%dlink · d-view 8May 23, 2024
- CVE-2021-2738939Monitor
A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30).
CriticalCVSS 9.8No exploitEPSS 1%siemens · opcenter qualityApr 22, 2021
- CVE-2021-3252039Monitor
QSAN Storage Manager - Use of Hard-coded Cryptographic Key
CriticalCVSS 9.8No exploitEPSS 1%qsan · storage managerJul 7, 2021
- CVE-2023-3793639Monitor
A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 throug
CriticalCVSS 9.8No exploitEPSS 1%fortinet · fortiswitchJan 14, 2025