CWE-1394 · 18 kayıt
Use of Default Cryptographic Key
Bu sınıftaki CVE’ler
18 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-48956İstismar yok | Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to aCWE-1394 | Kritik9,8 | — | %0,9 | 9 Ara 2024 |
39İzleyin | CVE-2025-44954İstismar yok | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.commscope · ruckus smartzone firmware · CWE-1394 | Kritik9,8 | — | %0,7 | 4 Ağu 2025 |
39İzleyin | CVE-2025-41742İstismar yok | Sprecher Automation: SPRECON-E series has a critical vulnerability due to the use of static cryptographic keys in system componentssprecher-automation · sprecon-e-c firmware · CWE-1394 | Kritik9,8 | — | %0,5 | 2 Ara 2025 |
36İzleyin | CVE-2024-29037İstismar yok | Default secret use for initial deploymentdatahub · datahub-helm · CWE-1394 | Kritik9,1 | — | %0,6 | 20 Mar 2024 |
36İzleyin | CVE-2026-75870İstismar yok | Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secretCWE-1394 | Kritik9,1 | — | %0,5 | 22 Ağu 2026 |
36İzleyin | CVE-2025-41744İstismar yok | Sprecher Automation: SPRECON-E series has static default key material for TLS connectionssprecher-automation · sprecon-e-c firmware · CWE-1394 | Kritik9,1 | — | %0,4 | 2 Ara 2025 |
36İzleyin | CVE-2024-1275İstismar yok | Vulnerability in Baxter Welch Allyn Connex Spot Monitorbaxter · welch allyn connex spot monitor · CWE-1394 | Kritik9,1 | — | %0,4 | 31 May 2024 |
36İzleyin | CVE-2025-55049İstismar yok | Use of Default Cryptographic Key (CWE-1394)baicells · neutrino430 · CWE-1394 | Kritik9,1 | — | %0,3 | 9 Eyl 2025 |
30İzleyin | CVE-2023-6451İstismar yok | Publicly Known Cryptographic Machine Key In Procura Portal Applicationalayacare · procura · CWE-1394 | Yüksek7,5 | — | %0,5 | 16 Şub 2024 |
25İzleyin | CVE-2026-54887İstismar yok | DTLS server cookie bypass during startup window due to empty initial cookie secreterlang · erlang\/otp · CWE-1394 | Orta6,3 | — | %0,4 | 2 Tem 2026 |
24İzleyin | CVE-2026-5039İstismar yok | Predictable Default Cryptographic Key Used for DES Encryption in TP-Link TL-WL841Ntp-link · tl-wr841n firmware · CWE-1394 | Orta6,1 | — | %0,2 | 23 Nis 2026 |
23İzleyin | CVE-2026-20709İstismar yok | Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J SerieCWE-1394 | Orta5,8 | — | %0,1 | 8 Nis 2026 |
22İzleyin | CVE-2025-1688İstismar yok | System configuration password resetmilestone systems · xprotect vms · CWE-1394 | Orta5,5 | — | %0,2 | 15 Nis 2025 |
17İzleyin | CVE-2025-26849İstismar yok | There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions.docusnap · docusnap · CWE-1394 | Orta4,3 | — | %0,2 | 4 Mar 2025 |
12İzleyin | CVE-2026-25815İstismar yok | Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild ffortinet · fortios · CWE-1394 | Düşük3,2 | — | %0,1 | 5 Şub 2026 |
11İzleyin | CVE-2026-2215İstismar yok | rachelos WeRSS we-mp-rss JWT auth.py default keyrachelos · werss we-mp-rss · CWE-1394 | Düşük2,9 | — | %0,3 | 9 Şub 2026 |
9İzleyin | CVE-2024-11619İstismar yok | macrozheng mall JWT Token default keymacrozheng · mall · CWE-1394 | Düşük2,3 | — | %0,7 | 22 Kas 2024 |
8İzleyin | CVE-2024-10748İstismar yok | Cosmote Greece What's Up App Realm Database RealmDB.java default keycosmote · what\'s up · CWE-1394 | Düşük2,0 | — | %0,3 | 3 Kas 2024 |
- CVE-2024-4895639İzleyin
Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a
KritikCVSS 9,8İstismar yokEPSS %19 Ara 2024
- CVE-2025-4495439İzleyin
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.
KritikCVSS 9,8İstismar yokEPSS %1commscope · ruckus smartzone firmware4 Ağu 2025
- CVE-2025-4174239İzleyin
Sprecher Automation: SPRECON-E series has a critical vulnerability due to the use of static cryptographic keys in system components
KritikCVSS 9,8İstismar yokEPSS %0sprecher-automation · sprecon-e-c firmware2 Ara 2025
- CVE-2024-2903736İzleyin
Default secret use for initial deployment
KritikCVSS 9,1İstismar yokEPSS %1datahub · datahub-helm20 Mar 2024
- CVE-2026-7587036İzleyin
Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret
KritikCVSS 9,1İstismar yokEPSS %022 Ağu 2026
- CVE-2025-4174436İzleyin
Sprecher Automation: SPRECON-E series has static default key material for TLS connections
KritikCVSS 9,1İstismar yokEPSS %0sprecher-automation · sprecon-e-c firmware2 Ara 2025
- CVE-2024-127536İzleyin
Vulnerability in Baxter Welch Allyn Connex Spot Monitor
KritikCVSS 9,1İstismar yokEPSS %0baxter · welch allyn connex spot monitor31 May 2024
- CVE-2025-5504936İzleyin
Use of Default Cryptographic Key (CWE-1394)
KritikCVSS 9,1İstismar yokEPSS %0baicells · neutrino4309 Eyl 2025
- CVE-2023-645130İzleyin
Publicly Known Cryptographic Machine Key In Procura Portal Application
YüksekCVSS 7,5İstismar yokEPSS %1alayacare · procura16 Şub 2024
- CVE-2026-5488725İzleyin
DTLS server cookie bypass during startup window due to empty initial cookie secret
OrtaCVSS 6,3İstismar yokEPSS %0erlang · erlang\/otp2 Tem 2026
- CVE-2026-503924İzleyin
Predictable Default Cryptographic Key Used for DES Encryption in TP-Link TL-WL841N
OrtaCVSS 6,1İstismar yokEPSS %0tp-link · tl-wr841n firmware23 Nis 2026
- CVE-2026-2070923İzleyin
Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Serie
OrtaCVSS 5,8İstismar yokEPSS %08 Nis 2026
- CVE-2025-168822İzleyin
System configuration password reset
OrtaCVSS 5,5İstismar yokEPSS %0milestone systems · xprotect vms15 Nis 2025
- CVE-2025-2684917İzleyin
There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions.
OrtaCVSS 4,3İstismar yokEPSS %0docusnap · docusnap4 Mar 2025
- CVE-2026-2581512İzleyin
Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild f
DüşükCVSS 3,2İstismar yokEPSS %0fortinet · fortios5 Şub 2026
- CVE-2026-221511İzleyin
rachelos WeRSS we-mp-rss JWT auth.py default key
DüşükCVSS 2,9İstismar yokEPSS %0rachelos · werss we-mp-rss9 Şub 2026
- CVE-2024-116199İzleyin
macrozheng mall JWT Token default key
DüşükCVSS 2,3İstismar yokEPSS %1macrozheng · mall22 Kas 2024
- CVE-2024-107488İzleyin
Cosmote Greece What's Up App Realm Database RealmDB.java default key
DüşükCVSS 2,0İstismar yokEPSS %0cosmote · what\'s up3 Kas 2024