Falhas do tipo CWE-798

945 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2026-63239MEDIUMHard-coded AWS IAM credentials vulnerabilityEPSS 0.2%CVE-2025-2394MEDIUMDisclosure of Alibaba (OSS) Keys In Ecovacs Home Android and iOS Mobile ApplicationsEPSS 0.2%CVE-2023-33304MEDIUMA use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass sEPSS 0.2%CVE-2026-86555MEDIUMHardcoded Key Vulnerability in ZTE SmartLife APPEPSS 0.2%CVE-2025-53842MEDIUMUse of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerabilitEPSS 0.2%CVE-2023-41372HIGHThe vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client EPSS 0.2%CVE-2023-49221HIGHPrecor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and aEPSS 0.2%CVE-2023-40719MEDIUMA use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an atEPSS 0.2%CVE-2019-25722HIGHDräger SC Monitoring Devices Hard-coded Credentials and DoSEPSS 0.2%CVE-2026-36616MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS shared secret, WPS teEPSS 0.2%CVE-2025-63433MEDIUMXtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key EPSS 0.2%CVE-2023-44296HIGH Dell ELab-Navigator, version 3.1.9 contains a hard-coded credential vulnerability. A local attacker could potentially exploit this vulnerabEPSS 0.2%CVE-2025-23179MEDIUMRibbon Communications - CWE-798: Use of Hard-coded CredentialsEPSS 0.2%CVE-2025-55263HIGHHCL Aftermarket DPC is affected by Hardcoded Sensitive DataEPSS 0.2%CVE-2025-26398MEDIUMSolarWinds Database Performance Analyzer Hard-coded Cryptographic Key VulnerabilityEPSS 0.2%CVE-2025-1143HIGHBillion Electric M120N - Use of Hard-coded CredentialsEPSS 0.2%CVE-2024-50593HIGHHardcoded Service PasswordEPSS 0.2%CVE-2025-54465MEDIUMHard-coded Credentials Vulnerability in ZKTeco WL20EPSS 0.2%CVE-2026-19412HIGHHardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S RouterEPSS 0.2%CVE-2026-20111MEDIUMCisco Prime Infrastructure Stored Cross-Site Scripting VulnerabilityEPSS 0.2%