Vulnerabilities > Use of Hard-coded Credentials

DATE CVE VULNERABILITY TITLE RISK
2024-08-02 CVE-2024-33895 Use of Hard-coded Credentials vulnerability in Hms-Networks Ewon Cosy+ Firmware
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters.
low complexity
hms-networks CWE-798
6.6
2024-08-01 CVE-2024-7332 Use of Hard-coded Credentials vulnerability in Totolink Cp450 Firmware 4.1.0Cu.747B20191224
A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224.
network
low complexity
totolink CWE-798
critical
9.8
2024-07-28 CVE-2024-7170 Use of Hard-coded Credentials vulnerability in Totolink A3000Ru Firmware 5.9C.5185B20201128
A vulnerability was found in TOTOLINK A3000RU 5.9c.5185.
low complexity
totolink CWE-798
8.8
2024-07-28 CVE-2024-7155 Use of Hard-coded Credentials vulnerability in Totolink A3300R Firmware 17.0.0Cu.557B20221024
A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic.
local
high complexity
totolink CWE-798
4.7
2024-07-22 CVE-2024-6912 Use of Hard-coded Credentials vulnerability in Perkinelmer Processplus
Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.
network
low complexity
perkinelmer CWE-798
critical
9.8
2024-07-17 CVE-2024-5471 Use of Hard-coded Credentials vulnerability in Zohocorp Manageengine DDI Central 4001
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.
network
low complexity
zohocorp CWE-798
critical
9.8
2024-07-16 CVE-2024-35338 Use of Hard-coded Credentials vulnerability in Tendacn I29 Firmware 1.0.0.5
Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.
network
low complexity
tendacn CWE-798
critical
9.8
2024-07-09 CVE-2024-28747 An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.
network
low complexity
CWE-798
critical
9.8
2024-07-08 CVE-2023-46685 Use of Hard-coded Credentials vulnerability in Level1 Wbr-6013 Firmware Rer4Av3411B2T2Rlev09170623
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623.
network
low complexity
level1 CWE-798
critical
9.8
2024-07-02 CVE-2024-4708 Use of Hard-coded Credentials vulnerability in Myscada Mypro
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
network
low complexity
myscada CWE-798
critical
9.8