Fallos del tipo CWE-798

945 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2026-47255HIGHAgenticMail API/storage and outbound relay hardeningEPSS 0.3%CVE-2022-34840MEDIUMUse of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration seEPSS 0.3%CVE-2022-3089MEDIUMEnOcean SmartServer Hard-coded credentialsEPSS 0.3%CVE-2025-62777HIGHUse of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to lEPSS 0.3%CVE-2026-24346HIGHUse of well-known default credentials in EZCast Pro II DongleEPSS 0.3%CVE-2021-27430HIGHGE UR family hardcoded credentialsEPSS 0.2%CVE-2026-33072HIGHFileRise: Default Encryption Key Enables Token Forgery and Config DecryptionEPSS 0.2%CVE-2024-50690MEDIUMSunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmware updates.EPSS 0.2%CVE-2026-6374HIGHHardcoded Credentials in Zyxel WAH7601 RouterEPSS 0.2%CVE-2025-44643HIGHCertain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R v1.4.9. The settingEPSS 0.2%CVE-2022-32967LOWRealtek RTL8111EP-CG/RTL8111FP-CG - Use of Hard-coded CredentialsEPSS 0.2%CVE-2024-50692MEDIUMSunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands tEPSS 0.2%CVE-2026-12587HIGHEmbedded credentials in VirtuagymEPSS 0.2%CVE-2021-0245HIGHJunos OS: Junos Fusion: Hard-coded credentials on satellite devices allows a locally authenticated attacker to elevate their privileges.EPSS 0.2%CVE-2023-39458MEDIUMTriangle MicroWorks SCADA Data Gateway Use of Hard-coded Credentials Authentication Bypass VulnerabilityEPSS 0.2%CVE-2022-48067MEDIUMAn information disclosure vulnerability in Totolink A830R V4.1.2cu.5182 allows attackers to obtain the root password via a brute-force attacEPSS 0.2%CVE-2023-30351HIGHShenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is storedEPSS 0.2%CVE-2021-42850HIGHA weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that EPSS 0.2%CVE-2025-1879LOWi-Drive i11/i12 APK hard-coded credentialsEPSS 0.2%CVE-2024-27160MEDIUMHardcoded password used to encrypt logs and use of weak cipherEPSS 0.2%