Weaknesses of type CWE-798

943 results

Uso de credenciais hardcoded

Credenciais (senhas, chaves de API, tokens) embutidas no código-fonte ou binários da aplicação. O risco é que qualquer pessoa com acesso ao código ou arquivo compilado consegue extrair essas credenciais e abusar dos recursos protegidos, sem depender de quebra de senha ou ataque de força bruta.

Example

Um desenvolvedor coloca a senha do banco de dados como string literal dentro do código: `String connStr = "Server=db.empresa.com;Password=Admin123!";` Quando o código é compilado, a senha fica visível em ferramentas de análise binária ou se o repositório for exposto. Um atacante a encontra e acessa diretamente o banco.

How to mitigate

Armazene credenciais em variáveis de ambiente, secrets managers (como HashiCorp Vault, AWS Secrets Manager) ou arquivos de configuração protegidos fora do repositório. Nunca commite credenciais no Git; use .gitignore e ferramentas de scanning automático para evitar.

CVE-2025-4130HIGHHardcoded Credentials in PAVO Inc.'s PAVO PayEPSS 0.4%CVE-2025-52492HIGHA vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz, contains hard-codedEPSS 0.4%CVE-2023-6198CRITICALHard Coded CredentialEPSS 0.4%CVE-2026-42251HIGHHard-coded credentials in KS-SOMEDEPSS 0.4%CVE-2021-20025SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at iniEPSS 0.4%CVE-2020-37220HIGHHuawei HG630 V2 Router Authentication Bypass via Serial NumberEPSS 0.4%CVE-2025-4570MEDIUMAn insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used toEPSS 0.4%CVE-2026-86464CRITICALIn the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deploEPSS 0.4%CVE-2025-4569HIGHAn insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used toEPSS 0.4%CVE-2024-36556CRITICALForever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.EPSS 0.4%CVE-2026-10557CRITICALYarbo Android/iOS Mobile Application and Cloud Infrastructure Use of Hard-coded CredentialsEPSS 0.4%CVE-2025-51606HIGHhippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source cEPSS 0.4%CVE-2025-2343HIGHIROAD Dash Cam X5/Dash Cam X6 Device Pairing hard-coded credentialsEPSS 0.4%CVE-2019-20471HIGHAn issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup, a default password EPSS 0.4%CVE-2020-3234HIGHCisco IOS Software for Cisco Industrial Routers Virtual Device Server Static Credentials VulnerabilityEPSS 0.4%CVE-2017-12350A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to anEPSS 0.4%CVE-2026-45631CRITICALDokploy: Pre-Auth Admin Takeover via Hardcoded Authentication SecretEPSS 0.4%CVE-2026-11849CRITICALIEI Integration Corp|iRM-IEI Remote Management - Hard-coded CredentialsEPSS 0.4%CVE-2026-85148CRITICALLightstar|SmartIT Desktop Manager - Use of Hard-coded CredentialsEPSS 0.4%CVE-2026-85146CRITICALLightstar|SmartIT Desktop Manager - Use of Hard-coded CredentialsEPSS 0.4%