CWE-798 · 1,514 records
Hard-coded credentials
Why does it happen?
For convenience in support or manufacturing, an account that is identical on every device is embedded in the software. Credentials learned from one device work on all of them.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
const SUPPORT_USER = "support";const SUPPORT_PASS = "hardcoded-password";Fixed
const creds = await provisioning.deviceCredentials(deviceId);if (creds.mustRotate) await forcePasswordChange(deviceId);How to prevent it
- 01Assign unique credentials to each device during manufacturing.
- 02Require a password change at first setup.
- 03Automatically scan software packages for embedded secrets.
CVEs in this class
1,514 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
98Now | CVE-2022-26138Weaponized | The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users gatlassian · questions for confluence · CWE-798 | Critical9.8 | KEV | 98.2% | Jul 20, 2022 |
98Now | CVE-2024-3272Weaponized | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentialsdlink · dns-320l firmware · CWE-798 | Critical9.8 | KEV | 98.0% | Apr 3, 2024 |
97Now | CVE-2020-8657Weaponized | An issue was discovered in EyesOfNetwork 5.3.eyesofnetwork · eyesofnetwork · CWE-798 | Critical9.8 | KEV | 91.9% | Feb 6, 2020 |
94Now | CVE-2024-28987Weaponized | SolarWinds Web Help Desk Hardcoded Credential Vulnerabilitysolarwinds · web help desk · CWE-798 | Critical9.1 | KEV | 93.3% | Aug 21, 2024 |
74This week | CVE-2025-14611Weaponized | Gladinet CentreStack and TrioFox Hard Coded AES Keysgladinet · centrestack · CWE-798 | High7.1 | KEV | 53.3% | Dec 12, 2025 |
74This week | CVE-2026-22769Weaponized | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability.dell · recoverpoint for virtual machines · CWE-798 | Critical10.0 | KEV | 13.3% | Feb 17, 2026 |
68This week | CVE-2019-15975Weaponized | Cisco Data Center Network Manager Authentication Bypass Vulnerabilitiescisco · data center network manager · CWE-798 | Critical9.8 | — | 96.5% | Jan 6, 2020 |
67This week | CVE-2019-15976Proof of concept | Cisco Data Center Network Manager Authentication Bypass Vulnerabilitiescisco · data center network manager · CWE-798 | Critical9.8 | — | 92.8% | Jan 6, 2020 |
67This week | CVE-2021-44207Weaponized | Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.acclaimsystems · usaherds · CWE-798 | High8.1 | KEV | 17.6% | Dec 21, 2021 |
64This week | CVE-2019-1935Weaponized | Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerabilitycisco · integrated management controller supervisor · CWE-798 | Critical9.8 | — | 83.4% | Aug 21, 2019 |
62This week | CVE-2024-3408Weaponized | Authentication Bypass and RCE in man-group/dtaleman · d-tale · CWE-798 | Critical9.8 | — | 78.0% | Jun 6, 2024 |
62This week | CVE-2020-13166Weaponized | The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for allmylittletools · mylittleadmin · CWE-798 | Critical9.8 | — | 77.6% | May 19, 2020 |
62This week | CVE-2017-14143Weaponized | The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote atkaltura · kaltura server · CWE-798 | Critical9.8 | — | 77.4% | Sep 19, 2017 |
62This week | CVE-2022-1162Proof of concept | A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.gitlab · gitlab · CWE-798 | Critical9.8 | — | 75.6% | Apr 4, 2022 |
61This week | CVE-2020-11854Weaponized | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.microfocus · application performance management · CWE-798 | Critical9.8 | — | 74.4% | Oct 27, 2020 |
61This week | CVE-2016-1560Weaponized | ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for theexagrid · ex3000 firmware · CWE-798 | Critical9.8 | — | 72.3% | Apr 21, 2017 |
61This week | CVE-2020-4429Weaponized | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.ibm · data risk manager · CWE-798 | Critical9.8 | — | 72.0% | May 7, 2020 |
60This week | CVE-2023-22463Proof of concept | KubePi's Hardcoded Jwtsigkeys allows malicious actor to login with a forged JWT tokenfit2cloud · kubepi · CWE-798 | Critical9.8 | — | 69.7% | Jan 4, 2023 |
60This week | CVE-2023-5074Proof of concept | Authentication Bypass in D-Link D-View 8dlink · d-view 8 · CWE-798 | Critical9.8 | — | 69.6% | Sep 20, 2023 |
60This week | CVE-2014-9614Proof of concept | The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attacnetsweeper · netsweeper · CWE-798 | Critical9.8 | — | 68.7% | Feb 19, 2020 |
58Plan | CVE-2021-22707Proof of concept | A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlinschneider-electric · evlink city evc1s22p4 firmware · CWE-798 | Critical9.8 | — | 64.6% | Jul 21, 2021 |
58Plan | CVE-2023-28503Weaponized | Authentication bypass in UniRPC's udadmin servicerocketsoftware · unidata · CWE-798 | Critical9.8 | — | 62.1% | Mar 29, 2023 |
58Plan | CVE-2019-6693Weaponized | Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to thefortinet · fortios · CWE-798 | Medium6.5 | KEV | 5.8% | Nov 21, 2019 |
56Plan | CVE-2018-9161Proof of concept | Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account bprismaindustriale · checkweigher prismaweb · CWE-798 | Critical9.8 | — | 56.7% | Mar 31, 2018 |
54Plan | CVE-2018-15439Weaponized | Cisco Small Business Switches Privileged Access Vulnerabilitycisco · sg200-50 firmware · CWE-798 | Critical9.8 | — | 49.7% | Nov 8, 2018 |
- CVE-2022-2613898Now
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users g
CriticalCVSS 9.8KEVWeaponizedEPSS 98%atlassian · questions for confluenceJul 20, 2022
- CVE-2024-327298Now
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
CriticalCVSS 9.8KEVWeaponizedEPSS 98%dlink · dns-320l firmwareApr 3, 2024
- CVE-2020-865797Now
An issue was discovered in EyesOfNetwork 5.3.
CriticalCVSS 9.8KEVWeaponizedEPSS 92%eyesofnetwork · eyesofnetworkFeb 6, 2020
- CVE-2024-2898794Now
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
CriticalCVSS 9.1KEVWeaponizedEPSS 93%solarwinds · web help deskAug 21, 2024
- CVE-2025-1461174This week
Gladinet CentreStack and TrioFox Hard Coded AES Keys
HighCVSS 7.1KEVWeaponizedEPSS 53%gladinet · centrestackDec 12, 2025
- CVE-2026-2276974This week
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability.
CriticalCVSS 10.0KEVWeaponizedEPSS 13%dell · recoverpoint for virtual machinesFeb 17, 2026
- CVE-2019-1597568This week
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
CriticalCVSS 9.8WeaponizedEPSS 96%cisco · data center network managerJan 6, 2020
- CVE-2019-1597667This week
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
CriticalCVSS 9.8Proof of conceptEPSS 93%cisco · data center network managerJan 6, 2020
- CVE-2021-4420767This week
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
HighCVSS 8.1KEVWeaponizedEPSS 18%acclaimsystems · usaherdsDec 21, 2021
- CVE-2019-193564This week
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
CriticalCVSS 9.8WeaponizedEPSS 83%cisco · integrated management controller supervisorAug 21, 2019
- CVE-2024-340862This week
Authentication Bypass and RCE in man-group/dtale
CriticalCVSS 9.8WeaponizedEPSS 78%man · d-taleJun 6, 2024
- CVE-2020-1316662This week
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all
CriticalCVSS 9.8WeaponizedEPSS 78%mylittletools · mylittleadminMay 19, 2020
- CVE-2017-1414362This week
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote at
CriticalCVSS 9.8WeaponizedEPSS 77%kaltura · kaltura serverSep 19, 2017
- CVE-2022-116262This week
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.
CriticalCVSS 9.8Proof of conceptEPSS 76%gitlab · gitlabApr 4, 2022
- CVE-2020-1185461This week
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.
CriticalCVSS 9.8WeaponizedEPSS 74%microfocus · application performance managementOct 27, 2020
- CVE-2016-156061This week
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the
CriticalCVSS 9.8WeaponizedEPSS 72%exagrid · ex3000 firmwareApr 21, 2017
- CVE-2020-442961This week
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.
CriticalCVSS 9.8WeaponizedEPSS 72%ibm · data risk managerMay 7, 2020
- CVE-2023-2246360This week
KubePi's Hardcoded Jwtsigkeys allows malicious actor to login with a forged JWT token
CriticalCVSS 9.8Proof of conceptEPSS 70%fit2cloud · kubepiJan 4, 2023
- CVE-2023-507460This week
Authentication Bypass in D-Link D-View 8
CriticalCVSS 9.8Proof of conceptEPSS 70%dlink · d-view 8Sep 20, 2023
- CVE-2014-961460This week
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attac
CriticalCVSS 9.8Proof of conceptEPSS 69%netsweeper · netsweeperFeb 19, 2020
- CVE-2021-2270758Plan
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlin
CriticalCVSS 9.8Proof of conceptEPSS 65%schneider-electric · evlink city evc1s22p4 firmwareJul 21, 2021
- CVE-2023-2850358Plan
Authentication bypass in UniRPC's udadmin service
CriticalCVSS 9.8WeaponizedEPSS 62%rocketsoftware · unidataMar 29, 2023
- CVE-2019-669358Plan
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the
MediumCVSS 6.5KEVWeaponizedEPSS 6%fortinet · fortiosNov 21, 2019
- CVE-2018-916156Plan
Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account b
CriticalCVSS 9.8Proof of conceptEPSS 57%prismaindustriale · checkweigher prismawebMar 31, 2018
- CVE-2018-1543954Plan
Cisco Small Business Switches Privileged Access Vulnerability
CriticalCVSS 9.8WeaponizedEPSS 50%cisco · sg200-50 firmwareNov 8, 2018