Falhas do tipo CWE-798

943 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2025-10560CRITICALHardcoded cloud credentials in Worksnaps client application binaries expose production cloud resourcesEPSS 0.4%CVE-2024-37630HIGHD-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as roEPSS 0.4%CVE-2026-78251CRITICALDJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox DirectoryEPSS 0.4%CVE-2024-38281HIGHUse of Hard-coded Credentials in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)EPSS 0.4%CVE-2023-40236MEDIUMIn Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authenticatEPSS 0.4%CVE-2026-8605MEDIUMUse of Hard-coded Credentials in ScadaBREPSS 0.4%CVE-2024-8450HIGHPLANET Technology switch devices - Hard-coded SNMPv1 read-write community stringEPSS 0.4%CVE-2025-41710MEDIUMUse of Hard-coded Credentials in power analyzerEPSS 0.4%CVE-2026-19871CRITICALUse of hard-coded credentials in Prospero Flow CRM employee onboardingEPSS 0.4%CVE-2024-22813MEDIUMAn issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to overwrite the hardcoded IP address in the device memoEPSS 0.4%CVE-2023-4204MEDIUMNPort IAW5000A-I/O Series Hardcoded Credential VulnerabilityEPSS 0.4%CVE-2026-8982CRITICALHard-coded / Backdoor AccountsEPSS 0.4%CVE-2025-27488MEDIUMMicrosoft Windows Hardware Lab Kit (HLK) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-30701CRITICALThe web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the EPSS 0.4%CVE-2026-13446CRITICALLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.4%CVE-2026-26218CRITICALnewbee-mall Default Seeded Administrator Credentials Allow Account TakeoverEPSS 0.4%CVE-2025-35940HIGHHard-coded ArchiverSpaApi JWT Signing KeyEPSS 0.4%CVE-2024-3544HIGHLoadMaster Hardcoded SSH KeyEPSS 0.4%CVE-2025-40938CRITICALA vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmEPSS 0.4%CVE-2020-36915HIGHAdtec Digital SignEdje Digital Signage Player v2.08.28 Default CredentialsEPSS 0.4%