Falhas do tipo CWE-798

943 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2023-41919CRITICALUse of Hard-coded Credentials in Kiloview P1/P2 devicesEPSS 0.4%CVE-2024-38466CRITICALShenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.EPSS 0.4%CVE-2024-36782CRITICALTOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers tEPSS 0.4%CVE-2023-39422MEDIUMUse of Hard-coded Credentials in multiple /irmdata/api/ endpointsEPSS 0.4%CVE-2018-0141—A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to thEPSS 0.4%CVE-2019-25291CRITICALINIM Electronics Smartliving SmartLAN/G/SI <=6.x Hard-coded Credentials VulnerabilityEPSS 0.4%CVE-2026-7786CRITICALJinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter Use of Hard-coded CredentialsEPSS 0.4%CVE-2024-48007MEDIUMDell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could pEPSS 0.4%CVE-2025-52159HIGHHardcoded credentials in default configuration of PPress 0.0.9.EPSS 0.4%CVE-2025-55739MEDIUMapi: Shared OAuth Signing Key Between Different InstancesEPSS 0.4%CVE-2024-48126CRITICALHI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access.EPSS 0.4%CVE-2025-2765HIGHCarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass VulnerabilityEPSS 0.4%CVE-2024-7952HIGHDataEdgePlatform DataMosaix™ Private CloudEPSS 0.4%CVE-2018-14801—In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser passworEPSS 0.4%CVE-2026-82448CRITICALShinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcoded Child Node KeyEPSS 0.4%CVE-2026-71238CRITICALDjangoCRM - Hardcoded Django SECRET_KEY Enables Session and CSRF Token ForgeryEPSS 0.4%CVE-2024-52788HIGHTenda W9 v1.0.0.7(4456) was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as EPSS 0.4%CVE-2024-52789HIGHTenda W30E v2.0 V16.01.0.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in EPSS 0.4%CVE-2025-14126HIGHTOZED ZLT M30S/ZLT M30S PRO Web hard-coded credentialsEPSS 0.4%CVE-2025-30125CRITICALAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, EPSS 0.4%