Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Skybridge Mb A200 Firmware CRITICAL 9.8
CVE-2022-36560

Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passco…

Fix: after 01.00.04
Fix from $2,300 2022-08-29
A720r Firmware HIGH 7.8
CVE-2022-36610

TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

No fix yet
Fix from $1,950 2022-08-29
A800r Firmware HIGH 7.8
CVE-2022-36611

TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

No fix yet
Fix from $1,950 2022-08-29
A950rg Firmware HIGH 7.8
CVE-2022-36612

TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

No fix yet
Fix from $1,950 2022-08-29
N600r Firmware HIGH 7.8
CVE-2022-36613

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

No fix yet
Fix from $1,950 2022-08-29
A860r Firmware HIGH 7.8
CVE-2022-36614

TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

No fix yet
Fix from $1,950 2022-08-29
A3000ru Firmware HIGH 7.8
CVE-2022-36615

TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

No fix yet
Fix from $1,950 2022-08-29
A810r Firmware HIGH 7.8
CVE-2022-36616

TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

No fix yet
Fix from $1,950 2022-08-29
Emerge E3 Firmware HIGH 8.2
CVE-2022-31269EPSS 5%

Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This…

Fix: after 0.32-09c
Fix from $1,950 2022-08-25
Grandma2 Light Firmware HIGH 8.8
CVE-2022-30036

MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated net…

No fix yet
Fix from $1,950 2022-08-21
Mapgis Igserver HIGH 8.1
CVE-2022-36171

MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion.

No fix yet
Fix from $1,950 2022-08-19
Igserver HIGH 8.8
CVE-2022-36170

MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitrary file deletion.

No fix yet
Fix from $1,950 2022-08-19
Agileconfig CRITICAL 9.8
CVE-2022-35540

Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.

Fix: 1.6.8+
Fix from $2,300 2022-08-18
Cmdb CRITICAL 9.8
CVE-2022-1400

Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, …

Fix: 18.01.00+
Fix from $2,300 2022-08-17
Hulu HIGH 7.5
CVE-2022-35734

'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting …

Fix: 3.1.2+
Fix from $1,950 2022-08-16
Connect Secure HIGH 7.2
CVE-2021-44720

In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > P…

Fix: 9.1+
Fix from $1,950 2022-08-12
A3002ru Firmware CRITICAL 9.8
CVE-2022-35491

TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.

Mitigation only
Fix from $2,300 2022-08-10
Linkhub Mesh Wifi Ac1200 CRITICAL 9.8
CVE-2022-22144

A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. …

No fix yet
Fix from $2,300 2022-08-05
A3600r Firmware CRITICAL 9.8
CVE-2022-34993

Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.

No fix yet
Fix from $2,300 2022-08-04
Omicard Edm CRITICAL 9.8
CVE-2022-32965

OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to exec…

Fix: after 6.0
Fix from $2,300 2022-08-04
Vinchin Backup And Recovery CRITICAL 9.8
CVE-2022-35866

This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authenticat…

No fix yet
Fix from $2,300 2022-08-03
Twinsoft CRITICAL 9.8
CVE-2021-22644

Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.

Fix: 1.46 / 12.4+
Fix from $2,300 2022-07-28
Netbackup CRITICAL 9.8
CVE-2022-36952

In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through …

Fix: 8.3.0.2+
Fix from $2,300 2022-07-27
Ace1000 Firmware CRITICAL 9.8
CVE-2022-30271

The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only…

Mitigation only
Fix from $2,300 2022-07-26
Ace1000 Firmware CRITICAL 9.8
CVE-2022-30274

The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded…

Mitigation only
Fix from $2,300 2022-07-26
Openbsi MEDIUM 5.5
CVE-2022-29960

Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES…

Fix: 5.9+
Fix from $1,600 2022-07-26
Deltav Distributed Control System Sq Controller Firmware MEDIUM 5.5
CVE-2022-29962

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but …

Fix: after 2022-04-29
Fix from $1,600 2022-07-26
Deltav Distributed Control System Sq Controller Firmware MEDIUM 5.5
CVE-2022-29963

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides acces…

Fix: after 2022-04-29
Fix from $1,600 2022-07-26
Deltav Distributed Control System Sq Controller Firmware MEDIUM 5.5
CVE-2022-29964

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell…

Fix: after 2022-04-29
Fix from $1,600 2022-07-26
Bently Nevada 3701\/40 Firmware CRITICAL 9.8
CVE-2022-29953

The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, ha…

Fix: 4.1+
Fix from $2,300 2022-07-26