Weaknesses of type CWE-798

943 results

Uso de credenciais hardcoded

Credenciais (senhas, chaves de API, tokens) embutidas no código-fonte ou binários da aplicação. O risco é que qualquer pessoa com acesso ao código ou arquivo compilado consegue extrair essas credenciais e abusar dos recursos protegidos, sem depender de quebra de senha ou ataque de força bruta.

Example

Um desenvolvedor coloca a senha do banco de dados como string literal dentro do código: `String connStr = "Server=db.empresa.com;Password=Admin123!";` Quando o código é compilado, a senha fica visível em ferramentas de análise binária ou se o repositório for exposto. Um atacante a encontra e acessa diretamente o banco.

How to mitigate

Armazene credenciais em variáveis de ambiente, secrets managers (como HashiCorp Vault, AWS Secrets Manager) ou arquivos de configuração protegidos fora do repositório. Nunca commite credenciais no Git; use .gitignore e ferramentas de scanning automático para evitar.

CVE-2026-68950HIGHUse of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product LineupsEPSS 0.2%CVE-2026-13463HIGHDue to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulnerability []EPSS 0.2%CVE-2026-48243MEDIUMOpen ISES Tickets < 3.44.2 Hardcoded WhitePages API Key in wp1.phpEPSS 0.2%CVE-2026-85451HIGHMOOS core-moos through 10.4.0 Remote Process Termination via Hard-Coded Multicast PassphraseEPSS 0.2%CVE-2026-48245MEDIUMOpen ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in tables.phpEPSS 0.2%CVE-2026-27785HIGHMilesight Cameras Use of Hard-coded CredentialsEPSS 0.2%CVE-2026-40636CRITICALDell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerabiEPSS 0.2%CVE-2025-15628HIGHHardcoded Certificates in TP-Link Omada Device CommunicationsEPSS 0.2%CVE-2025-54341MEDIUMA vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuratiEPSS 0.2%CVE-2025-5023HIGHUse of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versiEPSS 0.2%CVE-2026-86150MEDIUMTenda CP3 hostapd hard-coded credentialsEPSS 0.2%CVE-2025-48413HIGHHard-coded OS root credentials in eCharge Hardy Barth cPH2 / cPP2 charging stationsEPSS 0.2%CVE-2020-36547MEDIUMGE Voluson S8 Service Browser hard-coded credentialsEPSS 0.2%CVE-2025-30198LOWECOVACS Vacuum and Base Station Hard-Coded WPA2-PSKEPSS 0.2%CVE-2024-54749HIGHUbiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as rootEPSS 0.2%CVE-2024-48971CRITICALClinician Password and Serial Number Clinician Password are hard-coded in Life2000 VentilatorEPSS 0.2%CVE-2026-75754CRITICALMissing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center aEPSS 0.2%CVE-2024-55027HIGHWeintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.EPSS 0.2%CVE-2023-40717MEDIUMA use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who managed to get a shell EPSS 0.2%CVE-2025-9309LOWTenda AC10 MD5 Hash shadow hard-coded credentialsEPSS 0.2%