Fallos del tipo CWE-798

943 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2025-10560CRITICALHardcoded cloud credentials in Worksnaps client application binaries expose production cloud resourcesEPSS 0.4%CVE-2024-37630HIGHD-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as roEPSS 0.4%CVE-2026-78251CRITICALDJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox DirectoryEPSS 0.4%CVE-2024-38281HIGHUse of Hard-coded Credentials in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)EPSS 0.4%CVE-2023-40236MEDIUMIn Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authenticatEPSS 0.4%CVE-2026-8605MEDIUMUse of Hard-coded Credentials in ScadaBREPSS 0.4%CVE-2024-8450HIGHPLANET Technology switch devices - Hard-coded SNMPv1 read-write community stringEPSS 0.4%CVE-2025-41710MEDIUMUse of Hard-coded Credentials in power analyzerEPSS 0.4%CVE-2026-19871CRITICALUse of hard-coded credentials in Prospero Flow CRM employee onboardingEPSS 0.4%CVE-2024-22813MEDIUMAn issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to overwrite the hardcoded IP address in the device memoEPSS 0.4%CVE-2023-4204MEDIUMNPort IAW5000A-I/O Series Hardcoded Credential VulnerabilityEPSS 0.4%CVE-2026-8982CRITICALHard-coded / Backdoor AccountsEPSS 0.4%CVE-2025-27488MEDIUMMicrosoft Windows Hardware Lab Kit (HLK) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-30701CRITICALThe web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the EPSS 0.4%CVE-2026-13446CRITICALLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.4%CVE-2026-26218CRITICALnewbee-mall Default Seeded Administrator Credentials Allow Account TakeoverEPSS 0.4%CVE-2025-35940HIGHHard-coded ArchiverSpaApi JWT Signing KeyEPSS 0.4%CVE-2024-3544HIGHLoadMaster Hardcoded SSH KeyEPSS 0.4%CVE-2025-40938CRITICALA vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmEPSS 0.4%CVE-2020-36915HIGHAdtec Digital SignEdje Digital Signage Player v2.08.28 Default CredentialsEPSS 0.4%