Weaknesses of type CWE-798

941 results

Uso de credenciais hardcoded

Credenciais (senhas, chaves de API, tokens) embutidas no código-fonte ou binários da aplicação. O risco é que qualquer pessoa com acesso ao código ou arquivo compilado consegue extrair essas credenciais e abusar dos recursos protegidos, sem depender de quebra de senha ou ataque de força bruta.

Example

Um desenvolvedor coloca a senha do banco de dados como string literal dentro do código: `String connStr = "Server=db.empresa.com;Password=Admin123!";` Quando o código é compilado, a senha fica visível em ferramentas de análise binária ou se o repositório for exposto. Um atacante a encontra e acessa diretamente o banco.

How to mitigate

Armazene credenciais em variáveis de ambiente, secrets managers (como HashiCorp Vault, AWS Secrets Manager) ou arquivos de configuração protegidos fora do repositório. Nunca commite credenciais no Git; use .gitignore e ferramentas de scanning automático para evitar.

CVE-2022-4611MEDIUMClick Studios Passwordstate hard-coded credentialsEPSS 1.2%CVE-2014-125121CRITICALArray Networks vAPV and vxAG Default Credential Privilege EscalationEPSS 1.2%CVE-2018-17896Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credeEPSS 1.2%CVE-2022-29889CRITICALA hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a haEPSS 1.2%CVE-2022-26672HIGHASUS WebStorage - Use of Hard-coded CredentialsEPSS 1.2%CVE-2024-31873HIGHIBM Security Verify Access Appliance information disclosureEPSS 1.2%CVE-2022-41540MEDIUMThe web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are ableEPSS 1.2%CVE-2019-6859A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication MoEPSS 1.2%CVE-2024-6633CRITICALInsecure Default in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)EPSS 1.2%CVE-2021-26611HIGHHejHome IP Camera use of hard-coded credentials vulnerabilityEPSS 1.2%CVE-2024-57040CRITICALTP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password fEPSS 1.2%CVE-2026-2616HIGHBeetel 777VR1 Web Management hard-coded credentialsEPSS 1.2%CVE-2022-30234CRITICALA CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtaiEPSS 1.1%CVE-2019-6812A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 which could cause a EPSS 1.1%CVE-2022-38116CRITICALLe-yan Co., Ltd. Personnel and Salary Management System - Hard-coded passwordEPSS 1.1%CVE-2025-20309CRITICALCisco Unified Communications Manager Static SSH Credentials VulnerabilityEPSS 1.1%CVE-2018-0041CRITICALContrail Service Orchestration: Hardcoded credentials for Keystone service.EPSS 1.1%CVE-2019-0022CRITICALJuniper ATP: Two hard coded credentials sharing the same password give an attacker the ability to take control of any installation of the software.EPSS 1.1%CVE-2021-34812MEDIUMUse of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitEPSS 1.1%CVE-2020-7501A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SPEPSS 1.1%