Falhas do tipo CWE-798

945 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2025-27255HIGHUse of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encryptEPSS 0.1%CVE-2026-25601MEDIUMCredential Exposure vulnerability in MEPIS RMEPSS 0.1%CVE-2016-20031MEDIUMZKTeco ZKBioSecurity 3.0 Local Authorization Bypass via visLogin.jspEPSS 0.1%CVE-2026-4219MEDIUMINDEX Conferences & Exhibitions Organization YWF BPOF APGCS App ae.index.apgcs BuildConfig.java hard-coded credentialsEPSS 0.1%CVE-2025-10609MEDIUMHardcoded Credentials in Logo Software's TigerWings ERPEPSS 0.1%CVE-2025-37111MEDIUMHard-Coded Authentication Keys found in SystemEPSS 0.1%CVE-2026-4993MEDIUMwandb OpenUI config.py hard-coded credentialsEPSS 0.1%CVE-2025-9380HIGHFNKvision Y215 CCTV Camera Firmware passwd hard-coded credentialsEPSS 0.1%CVE-2024-39582LOWDell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacker with local access EPSS 0.1%CVE-2025-58385HIGHIn DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (there is hard-coded anEPSS 0.1%CVE-2025-9731LOWTenda AC9 Administrative shadow hard-coded credentialsEPSS 0.1%CVE-2026-4216MEDIUMi-SENS SmartLog App air.SmartLog.android hard-coded credentialsEPSS 0.1%CVE-2025-55047HIGHCWE-798 Use of Hard-coded CredentialsEPSS 0.1%CVE-2026-49323MEDIUMIndian Scout Bobber 2025 WCM-to-ECM weak authenticationEPSS 0.1%CVE-2025-58744MEDIUMHard-Coded Default Credentials Enable Document Archive Decryption in Milner ImageDirector CaptureEPSS 0.1%CVE-2025-41380MEDIUMInjection vulnerability in Iridium Certus 700EPSS 0.1%CVE-2026-36606HIGHMercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key using single DES in EPSS 0.1%CVE-2025-9778LOWTenda W12 Administrative shadow hard-coded credentialsEPSS 0.1%CVE-2024-40410MEDIUMCybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.EPSS 0.1%CVE-2025-15371HIGHTenda i24 Shadow File hard-coded credentialsEPSS 0.1%