Skip to main content

Threats Tagged 'cwe-259'

View all threats tagged with 'cwe-259'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-259

Threats Tagged 'cwe-259'

Click on any threat for detailed analysis and mitigation recommendations

0

A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion

Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted.

Join the discussion

The Siklu EtherHaul 8010 device with firmware version siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b contains a hard-coded static root password. This vulnerability is identified as CVE-2025-57175 and is categorized under CWE-259. The presence of a static root password can allow unauthorized users with network access to gain high-level privileges on the device. The CVSS v3.1 base score is 6.4, indicating a medium severity level. No official patch or remediation guidance has been provided by the vendor as of the publication date. There are no known exploits in the wild reported at this time.

Join the discussion

A hardcoded password vulnerability exists in Yokogawa Electric Corporation's CENTUM VP products across multiple versions. The vulnerability involves a hardcoded password for the PROG user account used in CENTUM Authentication Mode. Exploitation requires an attacker to already have access to the HIS screen controls and the system to be configured in CTM authentication mode. The default permissions for the PROG user are limited, reducing the risk of critical operations being performed. The vulnerability is rated low severity with a CVSS score of 2.1. No patch or remediation information is provided in the available data.

Join the discussion

CVE-2025-59388 is a medium-severity vulnerability in QNAP Systems Inc. 's Hyper Data Protector version 2.3.x. It is caused by the use of a hard-coded password (CWE-259), which allows remote attackers to gain unauthorized access without any authentication or user interaction. The vulnerability has been fixed in version 2.3.1.455 and later. Exploitation requires no privileges and no user interaction, making it relatively easy to exploit remotely.

Join the discussion

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known.

Join the discussion

Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.

Join the discussion

The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5. This is due to the plugin using a hardcoded password for authentication in the QueryControllerAdmin::authenticated function. This makes it possible for unauthenticated attackers to create and sync products.

Join the discussion
0

An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded password embedded in publicly available software. This password can then be used to decrypt sensitive network traffic, affecting the Cognex device.

Join the discussion

A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.

Join the discussion

Showing 1 to 10 of 23 results

Filters:Tag: cwe-259
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses