Skip to content
Noroxi

CWE-798 · 1,514 records

Hard-coded credentials

Why does it happen?

For convenience in support or manufacturing, an account that is identical on every device is embedded in the software. Credentials learned from one device work on all of them.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

ts
const SUPPORT_USER = "support";const SUPPORT_PASS = "hardcoded-password";

Fixed

ts
const creds = await provisioning.deviceCredentials(deviceId);if (creds.mustRotate) await forcePasswordChange(deviceId);

How to prevent it

  1. 01Assign unique credentials to each device during manufacturing.
  2. 02Require a password change at first setup.
  3. 03Automatically scan software packages for embedded secrets.

CVEs in this class

1,514 records

All vulnerability classes