Falhas do tipo CWE-798

945 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2026-47255HIGHAgenticMail API/storage and outbound relay hardeningEPSS 0.3%CVE-2022-34840MEDIUMUse of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration seEPSS 0.3%CVE-2022-3089MEDIUMEnOcean SmartServer Hard-coded credentialsEPSS 0.3%CVE-2026-24346HIGHUse of well-known default credentials in EZCast Pro II DongleEPSS 0.3%CVE-2025-62777HIGHUse of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to lEPSS 0.3%CVE-2021-27430HIGHGE UR family hardcoded credentialsEPSS 0.2%CVE-2026-33072HIGHFileRise: Default Encryption Key Enables Token Forgery and Config DecryptionEPSS 0.2%CVE-2024-50690MEDIUMSunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmware updates.EPSS 0.2%CVE-2026-6374HIGHHardcoded Credentials in Zyxel WAH7601 RouterEPSS 0.2%CVE-2025-44643HIGHCertain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R v1.4.9. The settingEPSS 0.2%CVE-2022-32967LOWRealtek RTL8111EP-CG/RTL8111FP-CG - Use of Hard-coded CredentialsEPSS 0.2%CVE-2024-50692MEDIUMSunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands tEPSS 0.2%CVE-2026-12587HIGHEmbedded credentials in VirtuagymEPSS 0.2%CVE-2021-0245HIGHJunos OS: Junos Fusion: Hard-coded credentials on satellite devices allows a locally authenticated attacker to elevate their privileges.EPSS 0.2%CVE-2023-39458MEDIUMTriangle MicroWorks SCADA Data Gateway Use of Hard-coded Credentials Authentication Bypass VulnerabilityEPSS 0.2%CVE-2022-48067MEDIUMAn information disclosure vulnerability in Totolink A830R V4.1.2cu.5182 allows attackers to obtain the root password via a brute-force attacEPSS 0.2%CVE-2023-30351HIGHShenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is storedEPSS 0.2%CVE-2021-42850HIGHA weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that EPSS 0.2%CVE-2025-1879LOWi-Drive i11/i12 APK hard-coded credentialsEPSS 0.2%CVE-2024-27160MEDIUMHardcoded password used to encrypt logs and use of weak cipherEPSS 0.2%