<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Hardcoded Credentials (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/hardcoded.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/hardcoded-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Hardcoded Credentials (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:33 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2019-25722 – Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25722</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25722</strong></p>
  <p>Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denial-of-service vulnerability that allows local and remote attackers to compromise device integrity across all software versions. A local attacker with direct device access can use the hard-coded credentials to access service and clinical accounts and a…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42251 – Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker acces...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42251</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42251</strong></p>
  <p>Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a legitimate update.  This issue affects KS-SOMED with modules: KSPLUPDFTP.exe up to 30.00.00.056 and ANEKSKL…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44825 – Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44825</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44825</strong></p>
  <p>Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.   As an immediate workaround without upgrading, delete the template users (superadmin, a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42929 – Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42929</guid>
    <pubDate>Fri, 29 May 2026 19:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42929</strong></p>
  <p>Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24444 – SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24444</guid>
    <pubDate>Thu, 28 May 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24444</strong></p>
  <p>SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interface recovery endpoints (mgmt.php, npcmd.php) that allows unauthenticated attackers to gain root access by submitting the hardcoded credential to the recovery endpoint via HTTP. Attackers can leverage this hardcoded password to enable filtered SSH and…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5065 – IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credential...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5065</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5065</guid>
    <pubDate>Wed, 27 May 2026 14:17:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5065</strong></p>
  <p>IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5065">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7251 – Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded passw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7251</guid>
    <pubDate>Tue, 26 May 2026 18:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7251</strong></p>
  <p>Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9139 – Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded crede...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9139</guid>
    <pubDate>Wed, 20 May 2026 20:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9139</strong></p>
  <p>Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where authentication is implemented entirely in client-side JavaScript in login.zhtml, exposing static plaintext credentials in the page source. Unauthenticated attackers with network access can recover administrative credentials directly from the client-…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8605 – In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8605</guid>
    <pubDate>Tue, 19 May 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8605</strong></p>
  <p>In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68421 – Comarch ERP Optima client makes use of a hard-coded password for a database user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68421</guid>
    <pubDate>Thu, 14 May 2026 11:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68421</strong></p>
  <p>Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server. This issue has been fixed in version 2026.4</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40636 – Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40636</guid>
    <pubDate>Mon, 11 May 2026 10:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40636</strong></p>
  <p>Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8032 – A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8032</guid>
    <pubDate>Wed, 06 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8032</strong></p>
  <p>A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of the file /cdemos/echs/priv/echs.js. This manipulation of the argument ADMIN_KEY causes hard-coded credentials. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 5.7.1 is sufficient to resolve this issue. The…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41930 – Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41930</guid>
    <pubDate>Wed, 06 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41930</strong></p>
  <p>Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin container with pre-configured database credentials. Attackers can connect to the phpMyAdmin port to gain unrestricted read and write access to the entire Vvveb database, including administrator password…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7579 – A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7579</guid>
    <pubDate>Fri, 01 May 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7579</strong></p>
  <p>A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. This issue affects some unknown processing of the file astrbot/dashboard/routes/auth.py of the component Dashboard. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclo…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27785 – Specific firmware versions of Milesight AIOT camera firmware contain hard-coded ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27785</guid>
    <pubDate>Tue, 28 Apr 2026 00:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27785</strong></p>
  <p>Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6574 – A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6574</guid>
    <pubDate>Sun, 19 Apr 2026 14:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6574</strong></p>
  <p>A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpoint. Such manipulation of the argument key leads to hard-coded credentials. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this d…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5189 – CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5189</guid>
    <pubDate>Wed, 15 Apr 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5189</strong></p>
  <p>CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-9497 – Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9497</guid>
    <pubDate>Sat, 28 Mar 2026 11:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-9497</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27073 – Use of Hard-coded Credentials vulnerability in Addi Addi – Cuotas que se adaptan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27073</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27073</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Addi Addi – Cuotas que se adaptan a ti buy-now-pay-later-addi allows Password Recovery Exploitation.This issue affects Addi – Cuotas que se adaptan a ti: from n/a through <= 2.0.4.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1958 – Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1958</guid>
    <pubDate>Mon, 23 Mar 2026 13:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1958</strong></p>
  <p>Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several internal services. Critically, this included access to the FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a legitimate upd…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22900 – A use of hard-coded credentials vulnerability has been reported to affect QuNetS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22900</guid>
    <pubDate>Fri, 20 Mar 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22900</strong></p>
  <p>A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access.  We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4475 – A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_201710241...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4475</guid>
    <pubDate>Fri, 20 Mar 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4475</strong></p>
  <p>A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The affected element is an unknown function of the file home/web/ipc. Such manipulation leads to hard-coded credentials. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30701 – The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30701</guid>
    <pubDate>Wed, 18 Mar 2026 18:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30701</strong></p>
  <p>The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of Server Side Include) within multiple server-side web pages, including login.shtml and settings.shtml. These pages embed server-side execution directives that dynamically retrieve and expose the web administration password from non-volatile memory at r…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28674 – xiaoheiFS is a self-hosted financial and operational system for cloud service bu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28674</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28674</guid>
    <pubDate>Wed, 18 Mar 2026 01:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28674</strong></p>
  <p>xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the `AdminPaymentPluginUpload` endpoint lets admins upload any file to `plugins/payment/`. It only checks a hardcoded password (`qweasd123456`) and ignores file content. A background watcher (`StartWatcher`) then scans this folder every 5 seconds. If it finds a new exe…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28674">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-20026 – ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache To...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20026</guid>
    <pubDate>Mon, 16 Mar 2026 14:17:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-20026</strong></p>
  <p>ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives containing JSP applications and execute arbitrary code with SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3873 – Use of Hard-coded Credentials vulnerability in Avantra allows Accessing 
Functio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3873</guid>
    <pubDate>Fri, 13 Mar 2026 19:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3873</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Avantra allows Accessing  Functionality Not Properly Constrained by ACLs. This issue affects  Avantra: before 25.3.0.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28255 – A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28255</guid>
    <pubDate>Thu, 12 Mar 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28255</strong></p>
  <p>A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-59388 – A use of hard-coded password vulnerability has been reported to affect Hyper Dat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59388</guid>
    <pubDate>Thu, 12 Mar 2026 02:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-59388</strong></p>
  <p>A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access.  We have already fixed the vulnerability in the following version: Hyper Data Protector 2.3.1.455 and later</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-70041 – An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in osl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70041</guid>
    <pubDate>Wed, 11 Mar 2026 21:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-70041</strong></p>
  <p>An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24448 – Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24448</guid>
    <pubDate>Wed, 11 Mar 2026 06:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24448</strong></p>
  <p>Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70802 – Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70802</guid>
    <pubDate>Tue, 10 Mar 2026 21:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70802</strong></p>
  <p>Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70798 – Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70798</guid>
    <pubDate>Tue, 10 Mar 2026 21:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70798</strong></p>
  <p>Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13957 – CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause inf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13957</guid>
    <pubDate>Tue, 10 Mar 2026 18:17:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13957</strong></p>
  <p>CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29023 – Keygraph Shannon contains a hard-coded API key in its router configuration that,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29023</guid>
    <pubDate>Mon, 09 Mar 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29023</strong></p>
  <p>Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network attackers to authenticate using the publicly known static key. An attacker able to reach the router port can proxy requests through the Shannon instance using the victim’s configured upstream provider API credentials, resulting in unauthorized API usage…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28776 – International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28776</guid>
    <pubDate>Wed, 04 Mar 2026 08:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28776</strong></p>
  <p>International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can use these trivial, undocumented credentials to access the system via SSH. While initially dropped into a restricted shell, the attacker can trivially break out to achieve standard shell functionality.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-55021 – Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55021</guid>
    <pubDate>Tue, 03 Mar 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-55021</strong></p>
  <p>Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26985 – LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web app...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26985</guid>
    <pubDate>Wed, 25 Feb 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26985</strong></p>
  <p>LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Starting in version 24.0.0 and prior to versions 26.0.5, 27.0.2, and 28.0.0, an authenticated user with the appropriate authorization can read configuration files on the server by exploiting a path traversal vulnerability. Some of these fil…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67304 – In Ruckus Network Director (RND) &lt; 4.5.0.54, the OVA appliance contains hardcode...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67304</guid>
    <pubDate>Thu, 19 Feb 2026 20:25:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67304</strong></p>
  <p>In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network on TCP port 5432. An attacker can use the hardcoded credentials to authenticate remotely, gaining superuser access to the database. This allows creation of administrative users for…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22769 – Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22769</guid>
    <pubDate>Tue, 17 Feb 2026 20:22:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22769</strong></p>
  <p>Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upg…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-23647 – Glory RBG-100 recycler systems using the ISPK-08 software component contain hard...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23647</guid>
    <pubDate>Tue, 17 Feb 2026 17:21:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23647</strong></p>
  <p>Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user accounts, including accounts with administrative privileges, were found to have fixed, embedded passwords. An attacker with network access to exposed services such as SSH may authenticate using thes…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2616 – A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2616</guid>
    <pubDate>Tue, 17 Feb 2026 15:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2616</strong></p>
  <p>A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. It is advisable to modify the configuration settings. The vendor was contacte…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25322 – Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25322</guid>
    <pubDate>Thu, 12 Feb 2026 23:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25322</strong></p>
  <p>Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' in the hidden form input fields.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37135 – AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37135</guid>
    <pubDate>Sat, 07 Feb 2026 00:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37135</strong></p>
  <p>AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-69971 – FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-hel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69971</guid>
    <pubDate>Tue, 03 Feb 2026 18:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-69971</strong></p>
  <p>FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin tokens and bypass authentication to gain full administrative access.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1610 – A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1610</guid>
    <pubDate>Thu, 29 Jan 2026 19:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1610</strong></p>
  <p>A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipulation results in hard-coded credentials. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been made public and coul…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-40537 – SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40537</guid>
    <pubDate>Wed, 28 Jan 2026 08:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-40537</strong></p>
  <p>SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24840 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24840</guid>
    <pubDate>Wed, 28 Jan 2026 01:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24840</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.com/install.sh, line 154) uses a hardcoded password when creating the database container. This means that nearly all Dokploy installations use the same database credentials and could be compromised. Version 0.26.6 contai…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-59091 – Multiple hardcoded credentials have been identified, which are allowed to sign-i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59091</guid>
    <pubDate>Mon, 26 Jan 2026 10:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-59091</strong></p>
  <p>Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This information, among other things, is used to graphically visualize open doors and alerts. However, controlling the Access Managers via this interface is also possi…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58744 – Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58744</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58744</strong></p>
  <p>Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in    Milner ImageDirector Capture on Windows allows decryption of document archive files using credentials decrypted with hard-coded application encryption key.  This issue affects ImageDirector Capture: from 7.0.9.0 before 7.6.3.25808.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14115 – IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14115</guid>
    <pubDate>Tue, 20 Jan 2026 15:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14115</strong></p>
  <p>IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBM® Sterling Connect:Direct for UNIX contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1221 – PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS  has a Use of Hard...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1221</guid>
    <pubDate>Tue, 20 Jan 2026 07:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1221</strong></p>
  <p>PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS  has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to the database using hardcoded database credentials stored in the firmware.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-69426 – The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69426</guid>
    <pubDate>Fri, 09 Jan 2026 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-69426</strong></p>
  <p>The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables SCP and pseudo-TTY allocation, an attacker can authenticate using the hardcoded credentials and establish SSH local port f…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-7072 – The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credential...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7072</guid>
    <pubDate>Fri, 09 Jan 2026 12:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-7072</strong></p>
  <p>The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an unauthenticated remote attacker could use to execute commands with root privileges. This vulnerability has been fixed in firmware version: 1.00.67 for CG3000TC and 1.00.27 for CG3000T.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25291 – INIM Electronics Smartliving SmartLAN/G/SI &lt;=6.x contains hard-coded credentials...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25291</guid>
    <pubDate>Thu, 08 Jan 2026 00:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25291</strong></p>
  <p>INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47744 – Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47744</guid>
    <pubDate>Wed, 31 Dec 2025 19:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47744</strong></p>
  <p>Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes root access. Attackers can exploit the static 'Chameleon' password to gain remote root access via Telnet or SSH on affected devices.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15371 – A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, No...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15371</guid>
    <pubDate>Wed, 31 Dec 2025 01:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15371</strong></p>
  <p>A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. Affected is an unknown function of the component Shadow File. Such manipulation with the input Fireitup leads to hard-coded credentials. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-53983 – Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53983</guid>
    <pubDate>Tue, 30 Dec 2025 23:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-53983</strong></p>
  <p>Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-50696 – SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50696</guid>
    <pubDate>Tue, 30 Dec 2025 23:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-50696</strong></p>
  <p>SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-33222 – NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33222</guid>
    <pubDate>Tue, 23 Dec 2025 17:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-33222</strong></p>
  <p>NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and data tampering.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65857 – An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.00080...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65857</guid>
    <pubDate>Mon, 22 Dec 2025 22:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65857</strong></p>
  <p>An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7358 – Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7358</guid>
    <pubDate>Thu, 18 Dec 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7358</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse.This issue affects SoliClub: before 5.3.7.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1029 – Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1029</guid>
    <pubDate>Thu, 18 Dec 2025 15:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1029</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. SoliClub allows Read Sensitive Constants Within an Executable.This issue affects SoliClub: from 5.2.4 before 5.3.7.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-47731 – Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47731</guid>
    <pubDate>Tue, 09 Dec 2025 21:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-47731</strong></p>
  <p>Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocumented page. Attackers can exploit the hidden endpoint by using the hard-coded password 'Selea781830' to enable configuration upload and overwrite device settings.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14126 – A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14126</guid>
    <pubDate>Sat, 06 Dec 2025 10:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14126</strong></p>
  <p>A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the component Web Interface. Such manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65730 – Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65730</guid>
    <pubDate>Fri, 05 Dec 2025 16:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65730</strong></p>
  <p>Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens used for authentication.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-29268 – ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29268</guid>
    <pubDate>Thu, 04 Dec 2025 20:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-29268</strong></p>
  <p>ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64778 – NMIS/BioDose software V22.02 and previous versions contain executable binaries w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64778</guid>
    <pubDate>Tue, 02 Dec 2025 21:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64778</strong></p>
  <p>NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application and database.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-25126 – Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25126</guid>
    <pubDate>Mon, 24 Nov 2025 21:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-25126</strong></p>
  <p>Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and an OS command injection flaw in its configuration services. The web/API interface accepts HTTP/XML requests authenticated with a fixed vendor credential string and passes user-controlled fields into shell execution contexts without proper argument s…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31649 – A hard-coded password vulnerability exists in the ControlVault WBDI Driver funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31649</guid>
    <pubDate>Mon, 17 Nov 2025 23:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31649</strong></p>
  <p>A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to execute priviledged operation. An attacker can issue an api call to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13252 – A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13252</guid>
    <pubDate>Sun, 16 Nov 2025 23:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13252</strong></p>
  <p>A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Affected by this issue is some unknown functionality of the component RSA/OAuth2/Database. The manipulation results in hard-coded credentials. The attack can be executed remotely. The exploit has been made public and could be used. This product implements a rolling release for ongoing de…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64308 – The Brightpick Mission Control web application exposes hardcoded credentials in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64308</guid>
    <pubDate>Sat, 15 Nov 2025 00:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64308</strong></p>
  <p>The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-523</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34501 – Deck Mate 2 is distributed with static, hard-coded credentials for the root shel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34501</guid>
    <pubDate>Mon, 03 Nov 2025 22:18:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34501</strong></p>
  <p>Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HTTP, Telnet, SMB, X11) are enabled by default. If an attacker can reach these interfaces - most often through local or near-local access such as connecting to the USB or Ethernet ports beneath the table - the built-in credentials permit administrative…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62777 – Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62777</guid>
    <pubDate>Tue, 28 Oct 2025 05:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62777</strong></p>
  <p>Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to log in to the affected device via Telnet and execute arbitrary commands.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10639 – The WorkExaminer Professional server installation comes with an FTP server that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10639</guid>
    <pubDate>Tue, 21 Oct 2025 12:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10639</strong></p>
  <p>The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with network access to this port can use weak hardcoded credentials to login to the FTP server and modify or read data, log files and gain remote code execution as NT Authority\SYSTEM on the server by exchanging accessible service binaries in the WorkEx…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-6950 – An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s net...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6950</guid>
    <pubDate>Fri, 17 Oct 2025 04:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-6950</strong></p>
  <p>An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated attacker to forge valid tokens, thereby bypassing authentication controls and impersonating any user. Exploitation of this vulne…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-10850 – The Felan Framework plugin for WordPress is vulnerable to improper authenticatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10850</guid>
    <pubDate>Thu, 16 Oct 2025 07:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-10850</strong></p>
  <p>The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password in the 'fb_ajax_login_or_register' function and in the 'google_ajax_login_or_register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they registered with facebook or google s…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36087 – IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36087</guid>
    <pubDate>Mon, 13 Oct 2025 01:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36087</strong></p>
  <p>IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11649 – A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. The affected elem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11649</guid>
    <pubDate>Sun, 12 Oct 2025 23:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11649</strong></p>
  <p>A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the component Root Account Handler. Performing manipulation results in use of hard-coded password. The attack must be initiated from a local position. The attack is considered to have high complexity. The exploitability is described as difficult. The exploit has been made public and could…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11284 – A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11284</guid>
    <pubDate>Sun, 05 Oct 2025 06:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11284</strong></p>
  <p>A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vulnerability is an unknown functionality of the file /index.php/auth/Ops/git of the component HTTP Header Handler. The manipulation of the argument Authorization leads to use of hard-coded password. The attack can be initiated remotely. The exploit has been disclosed to the public…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-59407 – The Flock Safety DetectionProcessing com.flocksafety.android.objects application...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59407</guid>
    <pubDate>Thu, 02 Oct 2025 17:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-59407</strong></p>
  <p>The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) bundles a Java Keystore (flock_rye.bks) along with its hardcoded password (flockhibiki17) in its code. The keystore contains a private key.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34196 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34196</guid>
    <pubDate>Mon, 29 Sep 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34196</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments) contain a hardcoded private key for the PrinterLogic Certificate Authority (CA) and a hardcoded password in product configuration files. The Windows client ships the CA certificate and its associated private key (and other sensitive settings such a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-11126 – A security flaw has been discovered in Apeman ID71 218.53.203.117. This vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11126</guid>
    <pubDate>Mon, 29 Sep 2025 00:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-11126</strong></p>
  <p>A security flaw has been discovered in Apeman ID71 218.53.203.117. This vulnerability affects unknown code of the file /system/www/system.ini. The manipulation results in hard-coded credentials. The attack may be performed from remote. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52159 – Hardcoded credentials in default configuration of PPress 0.0.9.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52159</guid>
    <pubDate>Fri, 19 Sep 2025 20:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52159</strong></p>
  <p>Hardcoded credentials in default configuration of PPress 0.0.9.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34197 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34197</guid>
    <pubDate>Fri, 19 Sep 2025 19:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34197</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951, Application prior to 20.0.2368 (VA and SaaS deployments) contain an undocumented local user account named ubuntu with a preset password and a sudoers entry granting that account passwordless root privileges (ubuntu ALL=(ALL) NOPASSWD: ALL). Anyone who knows the hardcoded password can obtain root privileges via…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54754 – An attacker with adjacent access, without authentication, can exploit 
this vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54754</guid>
    <pubDate>Thu, 18 Sep 2025 21:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54754</strong></p>
  <p>An attacker with adjacent access, without authentication, can exploit  this vulnerability to retrieve a hard-coded password embedded in  publicly available software. This password can then be used to decrypt  sensitive network traffic, affecting the Cognex device.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48842 – Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLX...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48842</guid>
    <pubDate>Wed, 17 Sep 2025 15:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48842</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-56466 – Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56466</guid>
    <pubDate>Wed, 10 Sep 2025 15:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-56466</strong></p>
  <p>Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55047 – CWE-798 Use of Hard-coded Credentials</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55047</guid>
    <pubDate>Tue, 09 Sep 2025 19:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55047</strong></p>
  <p>CWE-798 Use of Hard-coded Credentials</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-8857 – Clinic Image System developed by Changing contains hard-coded Credentials, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8857</guid>
    <pubDate>Fri, 29 Aug 2025 04:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-8857</strong></p>
  <p>Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to log into the system using administrator credentials embedded in the source code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58081 – Use of hard-coded password issue/vulnerability in SS1 Ver.16.0.0.10 and earlier ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58081</guid>
    <pubDate>Thu, 28 Aug 2025 09:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58081</strong></p>
  <p>Use of hard-coded password issue/vulnerability in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to view arbitrary files with root privileges.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9380 – A vulnerability was identified in FNKvision Y215 CCTV Camera 10.194.120.40. Affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9380</guid>
    <pubDate>Sun, 24 Aug 2025 07:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9380</strong></p>
  <p>A vulnerability was identified in FNKvision Y215 CCTV Camera 10.194.120.40. Affected by this issue is some unknown functionality of the file /etc/passwd of the component Firmware. Such manipulation leads to hard-coded credentials. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-8730 – A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and clas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8730</guid>
    <pubDate>Fri, 08 Aug 2025 15:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-8730</strong></p>
  <p>A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to hard-coded credentials. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-7768 – Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credential...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7768</guid>
    <pubDate>Wed, 06 Aug 2025 21:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-7768</strong></p>
  <p>Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This vulnerability enables attackers to escalate privileges and take full control of the device, potentially modifying system settings, disrupting solar energy production, and interfering with safety mechanisms.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-44955 – RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-44955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-44955</guid>
    <pubDate>Mon, 04 Aug 2025 16:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-44955</strong></p>
  <p>RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31953 – HCL iAutomate includes hardcoded credentials which may result in potential expos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31953</guid>
    <pubDate>Thu, 24 Jul 2025 21:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31953</strong></p>
  <p>HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54455 – Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54455</guid>
    <pubDate>Wed, 23 Jul 2025 06:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54455</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54454 – Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54454</guid>
    <pubDate>Wed, 23 Jul 2025 06:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54454</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4130 – Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4130</guid>
    <pubDate>Mon, 21 Jul 2025 14:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4130</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-52376 – An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52376</guid>
    <pubDate>Tue, 15 Jul 2025 14:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-52376</strong></p>
  <p>An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotely enable the Telnet service without authentication, bypassing security controls. The Telnet server is then accessible with hard-coded credentials, allowing attackers to gain administrative shell access and execute arbitr…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-3621 – Vulnerabilities* in ActADUR local server product, developed and maintained by Pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3621</guid>
    <pubDate>Tue, 15 Jul 2025 08:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-3621</strong></p>
  <p>Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.    * vulnerabilities:   *    Improper Neutralization of Special Elements used in a Command ('Command Injection')   *  Use of Hard-coded Credentials   *  Improper Authentication   *  Binding to an Unrestricted IP Address    The vulnerability has been rated as critical…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3621">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
