The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
Volume of CVEs assigned to CWE-259 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
194 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5222CRITICAL A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of t | Sep 27, 2023 | 9.8 | 85 | NO | YES |
CVE-2024-7332CRITICAL A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the | Aug 1, 2024 | 9.8 | 51 | NO | YES |
CVE-2025-57788MEDIUM A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not elim | Aug 20, 2025 | 6.5 | 49 | NO | YES |
CVE-2025-8730CRITICAL A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component Web Interf | Aug 8, 2025 | 9.8 | 46 | NO | YES |
CVE-2012-5862HIGH These Sinapsi devices
store hard-coded passwords in the PHP file of the device. By using the
hard-coded passwords in the device, attackers can log into the device
with administra | Nov 23, 2012 | 10.0 | 45 | NO | YES |
CVE-2026-7251CRITICAL Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, | May 26, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-35905CRITICAL T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account. | Jun 4, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-22054HIGH Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations | Jun 3, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-2616CRITICAL A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to har | Feb 17, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-22055HIGH Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations. | Jun 3, 2026 | 8.8 | 35 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.