Fallos del tipo CWE-259

210 resultados

Senha hard-coded no código

Credenciais (usuário, senha, chave de API) embutidas diretamente no código-fonte ou binário da aplicação. O problema é que qualquer pessoa com acesso ao código (repositório, binário, decompilação) consegue extrair a credencial e acessar sistemas protegidos sem autenticação legítima.

Ejemplo

Um desenvolvedor escreve `db_password = 'admin123'` no arquivo de configuração versionado no Git, ou coloca uma chave AWS como string constante no código. Um atacante clona o repositório público, encontra a senha e acessa o banco de dados direto.

Cómo mitigar

Use variáveis de ambiente, secrets managers (HashiCorp Vault, AWS Secrets Manager) ou arquivos de configuração não versionados. Nunca versione credenciais; revise histórico do Git com ferramentas como `git-secrets` ou `TruffleHog` para credenciais já commitadas e as rotacione imediatamente.

CVE-2026-4475HIGHYi Technology YI Home Camera ipc hard-coded credentialsEPSS 0.3%CVE-2025-28031MEDIUMTOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.ini.EPSS 0.3%CVE-2025-46067HIGHAn issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js fileEPSS 0.3%CVE-2025-12676MEDIUMKiotViet Sync <= 1.8.5 - Use of Hard-coded Password to Authorization BypassEPSS 0.3%CVE-2026-93969MEDIUMaiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentialsEPSS 0.3%CVE-2026-93970MEDIUMaiyiyi121 SxDevOps Settings settings.py hard-coded credentialsEPSS 0.3%CVE-2026-70403CRITICALXING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected deEPSS 0.3%CVE-2026-90509MEDIUMdromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard-coded credentialsEPSS 0.3%CVE-2025-2556MEDIUMAudi UTR Dashcam Video Stream hard-coded credentialsEPSS 0.3%CVE-2026-7579MEDIUMAstrBotDevs AstrBot Dashboard auth.py hard-coded credentialsEPSS 0.3%CVE-2026-78062MEDIUMvas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentialsEPSS 0.3%CVE-2026-86276MEDIUMSourceCodester Syllabus-Aligned Learning Management & Examination System db.php hard-coded credentialsEPSS 0.3%CVE-2025-5379MEDIUMNuCom NC-WR744G Console Application hard-coded credentialsEPSS 0.3%CVE-2026-11552MEDIUMSourceCodester Onlne Examination & Learning Management System import_users.php hard-coded passwordEPSS 0.3%CVE-2026-8032MEDIUMPicoTronica e-Clinic Healthcare System ECHS echs.js hard-coded credentialsEPSS 0.3%CVE-2025-11643MEDIUMTomofun Furbo 360/Furbo Mini MQTT Client Certificate furbo_img hard-coded credentialsEPSS 0.3%CVE-2026-6574MEDIUMosuuu LightPicture API Upload Endpoint lp.sql hard-coded credentialsEPSS 0.3%CVE-2024-2197LOWChirp Systems Chirp Access Use of Hard-coded PasswordEPSS 0.3%CVE-2026-86673MEDIUMningzichun Student Management System Database Connection database.php mysqli_connect hard-coded credentialsEPSS 0.3%CVE-2026-82808MEDIUMInbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker.production-esm.js hard-coded credentialsEPSS 0.3%