Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Wifi Repeater Firmware CRITICAL 9.8
CVE-2017-8771

On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" pass…

Mitigation only
Fix from $2,300 2017-09-20
Wifi Repeater Firmware CRITICAL 9.8
CVE-2017-8772

On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" pass…

Mitigation only
Fix from $2,300 2017-09-20
Kaltura Server CRITICAL 9.8
CVE-2017-14143EPSS 75%

The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers t…

Patch available
Fix from $2,300 2017-09-19
Dir 850l Firmware CRITICAL 9.8
CVE-2017-14421

D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices have a hardcoded password of wrgac25_dlink.2013gui_dir850l for the Alphanetworks ac…

No fix yet
Fix from $2,300 2017-09-13
Dir 850l Firmware HIGH 7.5
CVE-2017-14422

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices use the same hardcoded /et…

No fix yet
Fix from $1,950 2017-09-13
Dir 850l Firmware HIGH 7.8
CVE-2017-14426

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0644 /var/etc/shadow …

No fix yet
Fix from $1,950 2017-09-13
Dir 850l Firmware HIGH 7.8
CVE-2017-14428

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/run/hostapd…

No fix yet
Fix from $1,950 2017-09-13
Mu553s Firmware CRITICAL 9.8
CVE-2017-11351

Axesstel MU553S MU55XS-V1.14 devices have a default password of admin for the admin account.

Mitigation only
Fix from $2,300 2017-09-13
U Verse Firmware HIGH 8.1
CVE-2017-14115

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanent-enable W…

No fix yet
Fix from $1,950 2017-09-03
U Verse Firmware HIGH 8.1
CVE-2017-14116

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver https ser…

No fix yet
Fix from $1,950 2017-09-03
Load Balancer CRITICAL 9.8
CVE-2014-8426

Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.

No fix yet
Fix from $2,300 2017-08-28
Mrd 305 Din Firmware HIGH 7.5
CVE-2016-5816

A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older t…

Mitigation only
Fix from $1,950 2017-08-25
Mrd 305 Din Firmware MEDIUM 5.3
CVE-2017-12709

A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.…

Mitigation only
Fix from $1,600 2017-08-25
Sunny Boy 3600 Firmware CRITICAL 9.8
CVE-2017-9852

An Incorrect Password Management issue was discovered in SMA Solar Technology products. Default passwords exist that are rarely changed. User passwor…

Mitigation only
Fix from $2,300 2017-08-05
Malion CRITICAL 9.8
CVE-2017-10818

MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection settings of…

Fix: after 5.2.1
Fix from $2,300 2017-08-04
Wn Ax1167gr Firmware HIGH 8.8
CVE-2017-2280

WN-AX1167GR firmware version 3.00 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary …

Mitigation only
Fix from $1,950 2017-08-02
Wn G300r3 Firmware HIGH 8.0
CVE-2017-2283

WN-G300R3 firmware version 1.0.2 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary c…

Fix: after 1.0.2
Fix from $1,950 2017-08-02
Deep Discovery Director CRITICAL 9.8
CVE-2017-11380

Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all …

Patch available
Fix from $2,300 2017-08-01
Heinekingmedia CRITICAL 9.8
CVE-2017-11129

An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The keystore is locked with a hard-coded password. Therefore, everyone …

Fix: after 1.7.5
Fix from $2,300 2017-08-01
Connex CRITICAL 9.8
CVE-2017-11743

MEDHOST Connex contains a hard-coded Mirth Connect admin credential that is used for customer Mirth Connect management access. An attacker with knowl…

Mitigation only
Fix from $2,300 2017-07-31
Dpc3939 Firmware HIGH 8.8
CVE-2017-9488

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) and DPC3941T (firmware version DPC3941_2.5s3_PROD…

No fix yet
Fix from $1,950 2017-07-31
Medhost Document Management System CRITICAL 9.1
CVE-2017-11693

MEDHOST Document Management System contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard…

Mitigation only
Fix from $2,300 2017-07-28
Medhost Document Management System CRITICAL 9.1
CVE-2017-11694

MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access. An attacker with knowledge of the hard-coded…

Mitigation only
Fix from $2,300 2017-07-28
Connex CRITICAL 9.8
CVE-2017-11614

MEDHOST Connex contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials a…

Mitigation only
Fix from $2,300 2017-07-25
Fortiwlm CRITICAL 9.8
CVE-2017-7336

A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgr…

Fix: after 8.3.0
Fix from $2,300 2017-07-22
Amosconnect CRITICAL 9.8
CVE-2017-3222EPSS 7%

Hard-coded credentials in AmosConnect 8 allow remote attackers to gain full administrative privileges, including the ability to execute commands on t…

Mitigation only
Fix from $2,300 2017-07-22
Dx 350 Firmware CRITICAL 9.8
CVE-2017-9932

Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb has a default password of admin for the admin account.

No fix yet
Fix from $2,300 2017-07-21
Dir 615 CRITICAL 9.8
CVE-2017-11436

D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attackers to obtain access via a TEL…

Fix: after 20.12ptb01
Fix from $2,300 2017-07-19
Emc M\&r CRITICAL 9.8
CVE-2017-8011EPSS 14%

EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all …

Fix: after 4.0.2
Fix from $2,300 2017-07-17
Junos CRITICAL 9.8
CVE-2017-2343

The Integrated User Firewall (UserFW) feature was introduced in Junos OS version 12.1X47-D10 on the Juniper SRX Series devices to provide simple inte…

Mitigation only
Fix from $2,300 2017-07-17