Weaknesses of type CWE-798

941 results

Uso de credenciais hardcoded

Credenciais (senhas, chaves de API, tokens) embutidas no código-fonte ou binários da aplicação. O risco é que qualquer pessoa com acesso ao código ou arquivo compilado consegue extrair essas credenciais e abusar dos recursos protegidos, sem depender de quebra de senha ou ataque de força bruta.

Example

Um desenvolvedor coloca a senha do banco de dados como string literal dentro do código: `String connStr = "Server=db.empresa.com;Password=Admin123!";` Quando o código é compilado, a senha fica visível em ferramentas de análise binária ou se o repositório for exposto. Um atacante a encontra e acessa diretamente o banco.

How to mitigate

Armazene credenciais em variáveis de ambiente, secrets managers (como HashiCorp Vault, AWS Secrets Manager) ou arquivos de configuração protegidos fora do repositório. Nunca commite credenciais no Git; use .gitignore e ferramentas de scanning automático para evitar.

CVE-2022-22512CRITICALVARTA: Multiple devices prone to hard-coded credentialsEPSS 0.7%CVE-2022-41397CRITICALThe optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKeEPSS 0.7%CVE-2021-45106A vulnerability has been identified in SICAM TOOLBOX II (All versions). Affected applications use a circumventable access control within a dEPSS 0.7%CVE-2025-4041CRITICALUse of Hard-coded Credentials Optigo Networks ONS NC600EPSS 0.7%CVE-2023-2611CRITICALAdvantech R-SeeNet Use of Hard-coded CredentialsEPSS 0.7%CVE-2024-53356CRITICALWeak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escaEPSS 0.7%CVE-2026-61740CRITICALLightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protectionEPSS 0.7%CVE-2024-24324CRITICALTOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.EPSS 0.7%CVE-2023-30352CRITICALShenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.EPSS 0.7%CVE-2022-27506Hard-coded credentials allow administrators to access the shell via the SD-WAN CLIEPSS 0.7%CVE-2023-53983CRITICALAnevia Flamingo XL/XS 3.6.20 Default Credentials Authentication BypassEPSS 0.7%CVE-2025-8231HIGHD-Link DIR-890L UART Port rgbin hard-coded credentialsEPSS 0.7%CVE-2023-24147HIGHTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/conEPSS 0.7%CVE-2022-40242HIGHMegaRAC Default Credentials VulnerabilityEPSS 0.7%CVE-2026-7839CRITICALUltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin accessEPSS 0.7%CVE-2024-5514CRITICALMinMax CMS - Hidden FunctionalityEPSS 0.7%CVE-2023-46706CRITICALMachineSense FeverWarn Use of Hard-coded CredentialsEPSS 0.7%CVE-2019-17659LOWA use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH accEPSS 0.7%CVE-2024-23687CRITICALFOLIO mod-data-export-spring Hard-Coded CredentialsEPSS 0.7%CVE-2024-28747CRITICALifm: Use of Hard-coded CredentialsEPSS 0.7%