Threats Tagged 'cwe-798'
View all threats tagged with 'cwe-798'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-798'
Click on any threat for detailed analysis and mitigation recommendations
0 The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface. Join the discussion | CVE Database V5 | 09/24/2026, 20:25:02 UTC Added: 09/24/2026, 21:05:07 UTC |
Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data. Join the discussion | CVE Database V5 | 09/24/2026, 19:26:36 UTC Added: 09/24/2026, 19:33:30 UTC |
0 OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the account to authenticate to the password-reset workflow. The account does not provide normal administrator access; additional vulnerabilities are required to obtain an administrator takeover. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4. Join the discussion | CVE Database V5 | 09/22/2026, 23:10:16 UTC Added: 09/22/2026, 23:33:13 UTC |
0 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials. Join the discussion | CVE Database V5 | 09/22/2026, 21:37:11 UTC Added: 09/22/2026, 21:48:27 UTC |
0 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure. Join the discussion | CVE Database V5 | 09/22/2026, 14:10:30 UTC Added: 09/22/2026, 14:33:34 UTC |
The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it. Join the discussion | CVE Database V5 | 09/20/2026, 09:15:43 UTC Added: 09/20/2026, 09:32:06 UTC |
IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information. Join the discussion | GCVE Database | 09/18/2026, 21:32:26 UTC Added: 09/19/2026, 01:26:57 UTC |
Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker. Join the discussion | CVE Database V5 | 09/18/2026, 15:51:22 UTC Added: 09/18/2026, 16:02:22 UTC |
Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker. Join the discussion | CVE Database V5 | 09/18/2026, 15:43:54 UTC Added: 09/18/2026, 15:47:08 UTC |
0 CVE-2026-54767 is a critical vulnerability in LabRedesCefetRJ's WeGIA web manager for charitable institutions. Versions prior to 3.8.5 contain an unauthenticated GET endpoint that allows remote attackers to perform destructive database truncation operations without authorization. The vulnerability arises because the endpoint's access is controlled only by a hardcoded key embedded in the public source code. Exploitation can permanently delete member and contributor records. This issue is fixed in version 3.8.5. Join the discussion | CVE Database V5 | 09/17/2026, 21:56:28 UTC Added: 09/17/2026, 22:12:12 UTC |
Showing 1 to 10 of 265 results