Weaknesses of type CWE-798

943 results

Uso de credenciais hardcoded

Credenciais (senhas, chaves de API, tokens) embutidas no código-fonte ou binários da aplicação. O risco é que qualquer pessoa com acesso ao código ou arquivo compilado consegue extrair essas credenciais e abusar dos recursos protegidos, sem depender de quebra de senha ou ataque de força bruta.

Example

Um desenvolvedor coloca a senha do banco de dados como string literal dentro do código: `String connStr = "Server=db.empresa.com;Password=Admin123!";` Quando o código é compilado, a senha fica visível em ferramentas de análise binária ou se o repositório for exposto. Um atacante a encontra e acessa diretamente o banco.

How to mitigate

Armazene credenciais em variáveis de ambiente, secrets managers (como HashiCorp Vault, AWS Secrets Manager) ou arquivos de configuração protegidos fora do repositório. Nunca commite credenciais no Git; use .gitignore e ferramentas de scanning automático para evitar.

CVE-2024-28751CRITICALifm: Hardcoded telnet credentials in Smart PLCEPSS 0.6%CVE-2023-5456HIGHA CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacEPSS 0.6%CVE-2024-46429HIGHA hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management poEPSS 0.6%CVE-2026-23647CRITICALGlory RBG-100 Recycler System Hard-coded OS CredentialsEPSS 0.6%CVE-2023-20034HIGHVulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to EPSS 0.6%CVE-2025-7503CRITICALAn OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented, defaulEPSS 0.6%CVE-2024-42450CRITICALThe Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function EPSS 0.6%CVE-2022-50696CRITICALSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication BypassEPSS 0.6%CVE-2023-37857LOWPHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panelsEPSS 0.6%CVE-2024-39208CRITICALluci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.EPSS 0.6%CVE-2023-41878MEDIUMWeak password of selenium VNC in MeterSphereEPSS 0.6%CVE-2022-41399HIGHThe optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypEPSS 0.6%CVE-2023-36817HIGHThe King's Temple Church website Leaked Stripe API Key in Public Code RepositoryEPSS 0.6%CVE-2025-57577HIGHAn issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's positiEPSS 0.6%CVE-2023-48250HIGHThe vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded acEPSS 0.6%CVE-2024-51431HIGHLB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.EPSS 0.6%CVE-2025-9310MEDIUMyeqifu carRental Druid login.html hard-coded credentialsEPSS 0.6%CVE-2023-32274HIGHEnphase Installer Toolkit Android App Use of Hard-coded CredentialsEPSS 0.6%CVE-2022-3927HIGHThe affected products store public and private key that are used to sign and protect custom parameter set files from modification.EPSS 0.6%CVE-2026-31928CRITICALDaktronics Controller Firmware Use of Hard-coded CredentialsEPSS 0.6%