CWE-259Variant1 in KEV

Use of Hard-coded Password

Draft in the CWE catalog · 166 CVEs mapped

166
CVEs mapped
1
In KEV
7.1
Median CVSS
What it is

The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

Recent examples
4.1cvss
CVE-2026-86150

CVE-2026-86150 - MEDIUM Severity Vulnerability

A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

MEDIUMno explanation yet
epss
9.8cvss
CVE-2026-70403

CVE-2026-70403 - CRITICAL Severity Vulnerability

XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.

CRITICALno explanation yet
0%
epss
7.3cvss
CVE-2026-82808

CVE-2026-82808 - HIGH Severity Vulnerability

A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the component Google OAuth Client Secret. Such manipulation leads to hard-coded credentials. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was informed beforehand about the issue. The support explains, that "[a]t the moment, the [bug bounty] programme is on hold while we work through a large number of existing reports."

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-259
Abstraction
Variant
Structure
Simple
Status
Draft
References (4)