Threats Tagged 'cwe-321'
View all threats tagged with 'cwe-321'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-321'
Click on any threat for detailed analysis and mitigation recommendations
The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network. Join the discussion | CVE Database V5 | 09/24/2026, 20:11:19 UTC Added: 09/24/2026, 20:33:29 UTC |
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 until 2.5.1, Termix derives the keys that wrap OIDC and WebAuthn users' Data Encryption Keys from committed default strings and the public userId salt in src/backend/utils/user-crypto.ts. Because OIDC_SYSTEM_SECRET and WEBAUTHN_SYSTEM_SECRET are not configured by the project's default deployment artifacts, an attacker with an offline SQLite database copy can derive the wrapping key, recover each affected user's DEK, and decrypt stored SSH passwords, private keys, and key passphrases. Password-authenticated users are not affected by this specific key derivation path. This issue is fixed in version 2.5.1. Join the discussion | CVE Database V5 | 09/24/2026, 16:01:42 UTC Added: 09/24/2026, 16:33:22 UTC |
0 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key. Join the discussion | CVE Database V5 | 09/23/2026, 15:43:29 UTC Added: 09/23/2026, 19:03:14 UTC |
0 ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources. Join the discussion | CVE Database V5 | 09/23/2026, 13:11:31 UTC Added: 09/23/2026, 13:33:29 UTC |
0 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key. Join the discussion | CVE Database V5 | 09/22/2026, 22:07:40 UTC Added: 09/22/2026, 22:18:14 UTC |
lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg and redistribute it to every container or virtual machine created from that image. An attacker who controls an HTTP package mirror or can intercept mirror traffic can use the shared pacman signing private key to sign modified packages that affected clients accept as trusted. Installing those packages permits arbitrary code execution as root on the client system. This issue is fixed in Arch Linux images published on or after 2026-05-28. Join the discussion | CVE Database V5 | 09/17/2026, 18:21:21 UTC Added: 09/17/2026, 18:32:08 UTC |
0 SolarWinds Access Rights Manager contains a vulnerability due to the use of a hard-coded cryptographic key. This flaw allows unauthenticated remote code execution, posing a high risk to confidentiality, integrity, and availability of the affected system. Join the discussion | CVE Database V5 | 09/17/2026, 16:30:31 UTC Added: 09/17/2026, 22:12:17 UTC |
0 Dell OpenManage Server Administrator Managed Node for Windows versions prior to 11.1.0.3 contain a vulnerability involving the use of a hard-coded cryptographic key. This flaw could allow an unauthenticated remote attacker to gain unauthorized access. The vulnerability is identified as CWE-321 and has a high severity rating with a CVSS score of 8.1. A fix is available in version 11.1.0.3. Join the discussion | CVE Database V5 | 09/17/2026, 11:21:12 UTC Added: 09/17/2026, 11:32:08 UTC |
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions. Join the discussion | CVE Database V5 | 09/17/2026, 07:59:52 UTC Added: 09/17/2026, 08:17:16 UTC |
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions. Join the discussion | CVE Database V5 | 09/17/2026, 04:01:12 UTC Added: 09/17/2026, 08:02:12 UTC |
Showing 1 to 10 of 131 results