Fallos del tipo CWE-798

943 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2026-42869CRITICALSOCFortress CoPilot: Hardcoded JWT secret allows unauthenticated full admin compromise and lateral movement into all integrated SOC toolsEPSS 0.4%CVE-2025-30113CRITICALAn issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. TEPSS 0.4%CVE-2025-30122CRITICALAn issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for EPSS 0.4%CVE-2025-30123CRITICALAn issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the FTPX user account, enEPSS 0.4%CVE-2026-48031CRITICALGo Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token ForgeryEPSS 0.4%CVE-2024-6656HIGHHardcoded Credentals in TNB Mobile Solutions' Cockpit SoftwareEPSS 0.4%CVE-2025-63823CRITICALMy Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass EPSS 0.4%CVE-2024-36480CRITICALUse of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an atEPSS 0.4%CVE-2026-41446CRITICALWattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic EndpointsEPSS 0.4%CVE-2025-65823CRITICALThe Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an aEPSS 0.4%CVE-2024-57811CRITICALIn Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH. The root password EPSS 0.4%CVE-2026-18452CRITICALRich Source|DMS+ (Non-Mobile) - Use of Hard-coded CredentialsEPSS 0.4%CVE-2025-71317CRITICALNetMan 204 Hard-coded Backdoor CredentialsEPSS 0.4%CVE-2026-8983CRITICALBackdoor Authentication TokenEPSS 0.4%CVE-2024-46508HIGHyeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEYEPSS 0.4%CVE-2023-46102HIGHThe Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands toEPSS 0.4%CVE-2025-2342MEDIUMIROAD X5 Mobile App API Endpoint hard-coded credentialsEPSS 0.4%CVE-2026-54767CRITICALWeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.phpEPSS 0.4%CVE-2026-46376CRITICALFreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP InterfaceEPSS 0.4%CVE-2025-57601CRITICALAiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access to all managed IoT/eEPSS 0.4%