Weaknesses of type CWE-321

362 results

Chave criptográfica hardcoded

É quando a chave ou senha usada para criptografia fica embutida no código-fonte ou binário da aplicação. Qualquer pessoa com acesso ao código (incluindo atacantes que fazem engenharia reversa) consegue extrair a chave e descriptografar todos os dados protegidos por ela, anulando completamente a proteção criptográfica.

Example

Um app mobile que faz login criptografa a senha com uma chave fixa como `const ENCRYPTION_KEY = '12345abc'` no código. Um atacante faz dump do APK, encontra a chave em minutos, e consegue descriptografar todas as senhas armazenadas de todos os usuários.

How to mitigate

Armazene chaves em repositórios seguros (key management systems, vaults como AWS Secrets Manager ou HashiCorp Vault), derive chaves de senhas do usuário com algoritmos fortes (PBKDF2, Argon2), ou use mecanismos de derivação dinâmica. Nunca coloque chaves no código, comentários ou arquivos de configuração versionados.

CVE-2026-1442HIGHUnitree UPK files Hard-Coded KeyEPSS 0.2%CVE-2024-52614MEDIUMUse of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions prior to 3.8.5. If thisEPSS 0.2%CVE-2021-27481ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcodEPSS 0.2%CVE-2026-49006MEDIUMTLS credential leakage vulnerability in ZTE F689 productEPSS 0.1%CVE-2025-6666LOWmotogadget mo.lock Ignition Lock NFC hard-coded keyEPSS 0.1%CVE-2026-5452MEDIUMUCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded keyEPSS 0.1%CVE-2026-5457MEDIUMPropertyGuru AgentNet Singapore App com.allproperty.android.agentnet BuildConfig.java hard-coded keyEPSS 0.1%CVE-2025-49164MEDIUMArris VIP1113 devices through 2025-05-30 with KreaTV SDK have a firmware decryption key of cd1c2d78f2cba1f73ca7e697b4a485f49a8a7d0c8b0fdc9f5EPSS 0.1%CVE-2025-30239HIGHSensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet DevicesEPSS 0.1%CVE-2021-23842MEDIUMUse of Hard-coded Cryptographic KeyEPSS 0.1%CVE-2026-5458MEDIUMNoelse Individuals & Pro App com.afone.noelse BuildConfig.java hard-coded keyEPSS 0.1%CVE-2025-56577HIGHAn issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the use of hard coded cryptographic keys.EPSS 0.1%CVE-2025-56801MEDIUMThe Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementEPSS 0.1%CVE-2026-5454MEDIUMGRID Organiser App co.gridapp.organiser app.json hard-coded keyEPSS 0.1%CVE-2026-5453MEDIUMRico só vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-coded keyEPSS 0.1%CVE-2026-5471MEDIUMInvestory Toy Planet Trouble App app.investory.toyfactory google-services-desktop.json hard-coded keyEPSS 0.1%CVE-2023-43637HIGHVault Key Partially PredeterminedEPSS 0.1%CVE-2025-34500HIGHShuffle Master Deck Mate 2 Insecure Update ChainEPSS 0.1%CVE-2025-11781HIGHUse of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.1%CVE-2025-30200LOWECOVACS Vacuum and Base Station Hard-Coded AES EncryptionEPSS 0.1%