Weaknesses of type CWE-798

943 results

Uso de credenciais hardcoded

Credenciais (senhas, chaves de API, tokens) embutidas no código-fonte ou binários da aplicação. O risco é que qualquer pessoa com acesso ao código ou arquivo compilado consegue extrair essas credenciais e abusar dos recursos protegidos, sem depender de quebra de senha ou ataque de força bruta.

Example

Um desenvolvedor coloca a senha do banco de dados como string literal dentro do código: `String connStr = "Server=db.empresa.com;Password=Admin123!";` Quando o código é compilado, a senha fica visível em ferramentas de análise binária ou se o repositório for exposto. Um atacante a encontra e acessa diretamente o banco.

How to mitigate

Armazene credenciais em variáveis de ambiente, secrets managers (como HashiCorp Vault, AWS Secrets Manager) ou arquivos de configuração protegidos fora do repositório. Nunca commite credenciais no Git; use .gitignore e ferramentas de scanning automático para evitar.

CVE-2024-39582LOWDell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacker with local access EPSS 0.1%CVE-2025-58385HIGHIn DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (there is hard-coded anEPSS 0.1%CVE-2025-9731LOWTenda AC9 Administrative shadow hard-coded credentialsEPSS 0.1%CVE-2025-58744MEDIUMHard-Coded Default Credentials Enable Document Archive Decryption in Milner ImageDirector CaptureEPSS 0.1%CVE-2026-4993MEDIUMwandb OpenUI config.py hard-coded credentialsEPSS 0.1%CVE-2025-55047HIGHCWE-798 Use of Hard-coded CredentialsEPSS 0.1%CVE-2025-41380MEDIUMInjection vulnerability in Iridium Certus 700EPSS 0.1%CVE-2026-29120CRITICALInsecure, Hardcoded Root Password Stored in Anaconda Configuration File On IDC SFX2100 Satellite ReceiverEPSS 0.1%CVE-2025-9778LOWTenda W12 Administrative shadow hard-coded credentialsEPSS 0.1%CVE-2024-40410MEDIUMCybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.EPSS 0.1%CVE-2026-17644HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.1%CVE-2026-36616MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS shared secret, WPS teEPSS 0.1%CVE-2025-30200LOWECOVACS Vacuum and Base Station Hard-Coded AES EncryptionEPSS 0.1%CVE-2024-3130MEDIUM Insecure Data Storage leading to sensitive Information disclosure.EPSS 0.1%CVE-2025-14096HIGHCredential Disclosure vulnerability in Radiometer ProductsEPSS 0.1%CVE-2025-15371HIGHTenda i24 Shadow File hard-coded credentialsEPSS 0.1%CVE-2025-66237HIGHSunbird DCIM dcTrack and Power IQ Use of Hard-coded CredentialsEPSS 0.1%CVE-2026-56269MEDIUMFlowise - Weak Default Token Hash Secret in JWT Token EncryptionEPSS 0.1%CVE-2023-20512LOWA hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug informaEPSS 0.1%CVE-2024-22313MEDIUMIBM Storage Defender - Resiliency Service information disclosureEPSS 0.1%