Threats Tagged 'cwe-321'
View all threats tagged with 'cwe-321'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-321'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-66763: CWE-321: Use of Hard-coded Cryptographic Key in SAP_SE SAP BusinessObjects Business Intelligence Platform (Central Management Server)CVE-2026-66763 0 SAP BusinessObjects Business Intelligence Platform (Central Management Server) contains a vulnerability where sensitive credentials are stored using a hard-coded cryptographic key. An attacker with high privileges and local access could decrypt these credentials, compromising confidentiality and integrity. There is no impact on availability. Join the discussion | CVE Database V5 | 08/11/2026, 00:17:50 UTC Added: 08/11/2026, 00:42:06 UTC |
CVE-2025-30239: CWE-321: Use of Hard-coded Cryptographic Key in TP-Link Systems Inc. HB810(US2) V1.0/1.6/2.0/2.6CVE-2025-30239 0 A vulnerability in TP-Link Systems Inc. HB810(US2) devices (versions V1.0, 1.6, 2.0, and 2.6) involves the use of hardcoded cryptographic keys embedded in the firmware. This flaw allows attackers with access to device storage to recover these keys and decrypt sensitive configuration data, including credentials and service-related information. The vulnerability has a high severity score of 8.5 and does not currently have an official patch or remediation guidance. Join the discussion | CVE Database V5 | 08/10/2026, 22:25:03 UTC Added: 08/10/2026, 22:42:08 UTC |
CVE-2026-54218: CWE-321 Use of hard-coded cryptographic key in Tobit Laboratories AG TeamDavidCVE-2026-54218 0 Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various files using only obfuscation. Any user with access to the server’s file system, or who can otherwise extract files from the server (see vulnerability “Random File Read”), can potentially obtain affected users’ passwords. This issue affects TeamDavid through Rollout 524. Join the discussion | CVE Database V5 | 08/07/2026, 09:49:24 UTC Added: 08/07/2026, 10:12:18 UTC |
CVE-2026-49008: CWE-321 Use of hard-coded cryptographic key in ZTE F689CVE-2026-49008 0 By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity verification of a specific application function on the device. Join the discussion | CVE Database V5 | 08/07/2026, 08:03:49 UTC Added: 08/07/2026, 08:41:43 UTC |
CVE-2026-49006: CWE-321 Use of hard-coded cryptographic key in ZTE F689CVE-2026-49006 0 By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission. Join the discussion | CVE Database V5 | 08/07/2026, 07:13:58 UTC Added: 08/07/2026, 07:41:50 UTC |
CVE-2026-18411: CWE-321 Use of hard-coded cryptographic key in Acrisure KARR BTCVE-2026-18411 0 The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization. Join the discussion | CVE Database V5 | 08/05/2026, 20:13:13 UTC Added: 08/05/2026, 20:56:46 UTC |
CVE-2026-14804: CWE-321 Use of hard-coded cryptographic key in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human ResourcesCVE-2026-14804 0 Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. Join the discussion | CVE Database V5 | 08/04/2026, 08:37:37 UTC Added: 08/04/2026, 09:18:34 UTC |
CVE-2026-18754: CWE-321 Use of hard-coded cryptographic key in GeoVision Inc. GV-AS1620 (GV-Cloud)CVE-2026-18754 0 The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. Join the discussion | CVE Database V5 | 08/04/2026, 07:09:17 UTC Added: 08/04/2026, 07:33:45 UTC |
CVE-2026-18753: CWE-321 Use of hard-coded cryptographic key in GeoVision Inc. GV-AS1620 (AS-Manager)CVE-2026-18753 0 The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. Join the discussion | CVE Database V5 | 08/04/2026, 07:08:40 UTC Added: 08/04/2026, 07:33:45 UTC |
CVE-2025-15627: CWE-321 Use of hard-coded cryptographic key in TP-Link Systems Inc. Omada GatewaysCVE-2025-15627 0 A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications. Join the discussion | CVE Database V5 | 08/03/2026, 17:49:46 UTC Added: 08/03/2026, 18:33:33 UTC |
Showing 1 to 10 of 16 results