Threats Tagged 'cwe-259'
View all threats tagged with 'cwe-259'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-259'
Click on any threat for detailed analysis and mitigation recommendations
0 A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 08/15/2026, 16:45:07 UTC Added: 08/15/2026, 16:56:46 UTC |
Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted. Join the discussion | CVE Database V5 | 05/26/2026, 17:06:46 UTC Added: 05/26/2026, 18:02:34 UTC |
The Siklu EtherHaul 8010 device with firmware version siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b contains a hard-coded static root password. This vulnerability is identified as CVE-2025-57175 and is categorized under CWE-259. The presence of a static root password can allow unauthorized users with network access to gain high-level privileges on the device. The CVSS v3.1 base score is 6.4, indicating a medium severity level. No official patch or remediation guidance has been provided by the vendor as of the publication date. There are no known exploits in the wild reported at this time. Join the discussion | CVE Database V5 | 04/08/2026, 00:00:00 UTC Added: 04/09/2026, 05:20:03 UTC |
0 A hardcoded password vulnerability exists in Yokogawa Electric Corporation's CENTUM VP products across multiple versions. The vulnerability involves a hardcoded password for the PROG user account used in CENTUM Authentication Mode. Exploitation requires an attacker to already have access to the HIS screen controls and the system to be configured in CTM authentication mode. The default permissions for the PROG user are limited, reducing the risk of critical operations being performed. The vulnerability is rated low severity with a CVSS score of 2.1. No patch or remediation information is provided in the available data. Join the discussion | CVE Database V5 | 03/30/2026, 00:01:11 UTC Added: 03/30/2026, 00:08:30 UTC |
CVE-2025-59388 is a medium-severity vulnerability in QNAP Systems Inc. 's Hyper Data Protector version 2.3.x. It is caused by the use of a hard-coded password (CWE-259), which allows remote attackers to gain unauthorized access without any authentication or user interaction. The vulnerability has been fixed in version 2.3.1.455 and later. Exploitation requires no privileges and no user interaction, making it relatively easy to exploit remotely. Join the discussion | CVE Database V5 | 03/12/2026, 01:41:44 UTC Added: 03/12/2026, 01:59:51 UTC |
0 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known. Join the discussion | CVE Database V5 | 02/06/2026, 18:57:31 UTC Added: 02/06/2026, 19:15:12 UTC |
Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system. Join the discussion | CVE Database V5 | 12/30/2025, 22:41:45 UTC Added: 12/30/2025, 22:58:54 UTC |
The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5. This is due to the plugin using a hardcoded password for authentication in the QueryControllerAdmin::authenticated function. This makes it possible for unauthenticated attackers to create and sync products. Join the discussion | CVE Database V5 | 11/05/2025, 07:27:56 UTC Added: 11/05/2025, 07:37:08 UTC |
0 An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded password embedded in publicly available software. This password can then be used to decrypt sensitive network traffic, affecting the Cognex device. Join the discussion | CVE Database V5 | 09/18/2025, 21:06:15 UTC Added: 09/18/2025, 21:14:19 UTC |
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk. Join the discussion | CVE Database V5 | 08/20/2025, 00:00:00 UTC Added: 08/20/2025, 03:47:47 UTC |
Showing 1 to 10 of 23 results