Vulnerabilities > Use of Hard-coded Credentials

DATE CVE VULNERABILITY TITLE RISK
2022-05-18 CVE-2021-42850 Use of Hard-coded Credentials vulnerability in Lenovo products
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.
local
low complexity
lenovo CWE-798
7.8
2022-05-18 CVE-2022-29644 Use of Hard-coded Credentials vulnerability in Totolink A3100R Firmware 4.1.2Cu.5050B20200504/4.1.2Cu.5247B20211129
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for the telnet service stored in the component /web_cste/cgi-bin/product.ini.
network
low complexity
totolink CWE-798
critical
9.8
2022-05-18 CVE-2022-29645 Use of Hard-coded Credentials vulnerability in Totolink A3100R Firmware 4.1.2Cu.5050B20200504/4.1.2Cu.5247B20211129
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for root stored in the component /etc/shadow.sample.
network
low complexity
totolink CWE-798
critical
9.8
2022-05-13 CVE-2022-1701 Use of Hard-coded Credentials vulnerability in Sonicwall products
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.
network
low complexity
sonicwall CWE-798
7.5
2022-05-12 CVE-2022-26020 Use of Hard-coded Credentials vulnerability in Inhandnetworks Ir302 Firmware 3.5.37
An information disclosure vulnerability exists in the router configuration export functionality of InHand Networks InRouter302 V3.5.4.
network
low complexity
inhandnetworks CWE-798
6.5
2022-05-12 CVE-2022-27172 Use of Hard-coded Credentials vulnerability in Inhandnetworks Ir302 Firmware 3.5.37/3.5.4
A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37.
network
low complexity
inhandnetworks CWE-798
8.8
2022-05-11 CVE-2021-38969 Use of Hard-coded Credentials vulnerability in IBM Spectrum Virtualize 8.2.0.0/8.3.0.0/8.4.0.0
IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials.
network
low complexity
ibm CWE-798
critical
9.8
2022-05-04 CVE-2022-23724 Use of Hard-coded Credentials vulnerability in Pingidentity Pingid Integration for Windows Login
Use of static encryption key material allows forging an authentication token to other users within a tenant organization.
network
low complexity
pingidentity CWE-798
8.1
2022-04-29 CVE-2022-29856 Use of Hard-coded Credentials vulnerability in Automationanywhere Automation 360 22
A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.
network
low complexity
automationanywhere CWE-798
7.5
2022-04-27 CVE-2021-34601 Use of Hard-coded Credentials vulnerability in Bender Cc612 Firmware and Icc15Xx Firmware
In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials.
network
low complexity
bender CWE-798
critical
9.8