<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Hardcoded Credentials</title>
  <link>https://cvedaily.com/pages/tags/hardcoded.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/hardcoded.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Hardcoded Credentials</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:33 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2019-25722 – Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25722</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25722</strong></p>
  <p>Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denial-of-service vulnerability that allows local and remote attackers to compromise device integrity across all software versions. A local attacker with direct device access can use the hard-coded credentials to access service and clinical accounts and a…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42251 – Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker acces...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42251</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42251</strong></p>
  <p>Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a legitimate update.  This issue affects KS-SOMED with modules: KSPLUPDFTP.exe up to 30.00.00.056 and ANEKSKL…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44825 – Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44825</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44825</strong></p>
  <p>Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.   As an immediate workaround without upgrading, delete the template users (superadmin, a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42929 – Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42929</guid>
    <pubDate>Fri, 29 May 2026 19:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42929</strong></p>
  <p>Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24444 – SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24444</guid>
    <pubDate>Thu, 28 May 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24444</strong></p>
  <p>SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interface recovery endpoints (mgmt.php, npcmd.php) that allows unauthenticated attackers to gain root access by submitting the hardcoded credential to the recovery endpoint via HTTP. Attackers can leverage this hardcoded password to enable filtered SSH and…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5065 – IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credential...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5065</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5065</guid>
    <pubDate>Wed, 27 May 2026 14:17:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5065</strong></p>
  <p>IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5065">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7251 – Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded passw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7251</guid>
    <pubDate>Tue, 26 May 2026 18:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7251</strong></p>
  <p>Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9139 – Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded crede...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9139</guid>
    <pubDate>Wed, 20 May 2026 20:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9139</strong></p>
  <p>Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where authentication is implemented entirely in client-side JavaScript in login.zhtml, exposing static plaintext credentials in the page source. Unauthenticated attackers with network access can recover administrative credentials directly from the client-…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8605 – In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8605</guid>
    <pubDate>Tue, 19 May 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8605</strong></p>
  <p>In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68421 – Comarch ERP Optima client makes use of a hard-coded password for a database user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68421</guid>
    <pubDate>Thu, 14 May 2026 11:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68421</strong></p>
  <p>Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server. This issue has been fixed in version 2026.4</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40636 – Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40636</guid>
    <pubDate>Mon, 11 May 2026 10:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40636</strong></p>
  <p>Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43826 – The OpenSearch logging provider, when configured with a `host` URL that embeds c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43826</guid>
    <pubDate>Mon, 11 May 2026 09:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43826</strong></p>
  <p>The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:password@server.example.com:9200`), wrote the full host URL — including the embedded credentials — into task logs. Any user with task-log read permission could harvest the backend credentials. Users are advised to upgrade to `apache-airflow-providers-opensearch` 1.9.1 or later and…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41018 – The Elasticsearch logging provider, when configured with a `host` URL that embed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41018</guid>
    <pubDate>Mon, 11 May 2026 09:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41018</strong></p>
  <p>The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:password@server.example.com:9200`), wrote the full host URL — including the embedded credentials — into task logs. Any user with task-log read permission could harvest the backend credentials. Users are advised to upgrade to `apache-airflow-providers-elasticsearch` 6.5.3 or lat…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8032 – A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8032</guid>
    <pubDate>Wed, 06 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8032</strong></p>
  <p>A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of the file /cdemos/echs/priv/echs.js. This manipulation of the argument ADMIN_KEY causes hard-coded credentials. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 5.7.1 is sufficient to resolve this issue. The…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41930 – Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41930</guid>
    <pubDate>Wed, 06 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41930</strong></p>
  <p>Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin container with pre-configured database credentials. Attackers can connect to the phpMyAdmin port to gain unrestricted read and write access to the entire Vvveb database, including administrator password…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7579 – A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7579</guid>
    <pubDate>Fri, 01 May 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7579</strong></p>
  <p>A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. This issue affects some unknown processing of the file astrbot/dashboard/routes/auth.py of the component Dashboard. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclo…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27785 – Specific firmware versions of Milesight AIOT camera firmware contain hard-coded ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27785</guid>
    <pubDate>Tue, 28 Apr 2026 00:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27785</strong></p>
  <p>Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-6610 – A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The imp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6610</guid>
    <pubDate>Mon, 20 Apr 2026 06:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-6610</strong></p>
  <p>A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Handler. Such manipulation of the argument USER/PASSWORD leads to hard-coded credentials. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. Th…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6578 – A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6578</guid>
    <pubDate>Sun, 19 Apr 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6578</strong></p>
  <p>A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component Setting Handler. The manipulation of the argument SECRET_KEY results in hard-coded credentials. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploi…</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6574 – A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6574</guid>
    <pubDate>Sun, 19 Apr 2026 14:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6574</strong></p>
  <p>A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpoint. Such manipulation of the argument key leads to hard-coded credentials. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this d…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5189 – CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5189</guid>
    <pubDate>Wed, 15 Apr 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5189</strong></p>
  <p>CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4832 – CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4832</guid>
    <pubDate>Tue, 14 Apr 2026 16:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4832</strong></p>
  <p>CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticated attacker is able to interrogate the SNMP port.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14944 – The Backup Migration plugin for WordPress is vulnerable to Missing Authorization...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14944</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14944</strong></p>
  <p>The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to a missing capability check on the 'initializeOfflineAjax' function and lack of proper nonce verification. The endpoint only validates against hardcoded tokens which are publicly exposed in the plugin's JavaScript. This makes it possible for unauthenticated a…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-7741 – Hardcoded Password Vulnerability have been found in CENTUM. Affected products co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7741</guid>
    <pubDate>Mon, 30 Mar 2026 00:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-7741</strong></p>
  <p>Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk that an attacker could log in as the PROG user.  The default permission for the PROG users is S1 permission (equivalent to OFFUSER). Therefore, for properly perm…</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-9497 – Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9497</guid>
    <pubDate>Sat, 28 Mar 2026 11:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-9497</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4993 – A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4993</guid>
    <pubDate>Sat, 28 Mar 2026 10:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4993</strong></p>
  <p>A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/openui/config.py. The manipulation of the argument LITELLM_MASTER_KEY leads to hard-coded credentials. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12708 – IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be ob...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12708</guid>
    <pubDate>Wed, 25 Mar 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12708</strong></p>
  <p>IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27073 – Use of Hard-coded Credentials vulnerability in Addi Addi – Cuotas que se adaptan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27073</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27073</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Addi Addi – Cuotas que se adaptan a ti buy-now-pay-later-addi allows Password Recovery Exploitation.This issue affects Addi – Cuotas que se adaptan a ti: from n/a through <= 2.0.4.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1958 – Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1958</guid>
    <pubDate>Mon, 23 Mar 2026 13:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1958</strong></p>
  <p>Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several internal services. Critically, this included access to the FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a legitimate upd…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22900 – A use of hard-coded credentials vulnerability has been reported to affect QuNetS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22900</guid>
    <pubDate>Fri, 20 Mar 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22900</strong></p>
  <p>A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access.  We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4475 – A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_201710241...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4475</guid>
    <pubDate>Fri, 20 Mar 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4475</strong></p>
  <p>A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The affected element is an unknown function of the file home/web/ipc. Such manipulation leads to hard-coded credentials. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30701 – The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30701</guid>
    <pubDate>Wed, 18 Mar 2026 18:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30701</strong></p>
  <p>The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of Server Side Include) within multiple server-side web pages, including login.shtml and settings.shtml. These pages embed server-side execution directives that dynamically retrieve and expose the web administration password from non-volatile memory at r…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28674 – xiaoheiFS is a self-hosted financial and operational system for cloud service bu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28674</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28674</guid>
    <pubDate>Wed, 18 Mar 2026 01:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28674</strong></p>
  <p>xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the `AdminPaymentPluginUpload` endpoint lets admins upload any file to `plugins/payment/`. It only checks a hardcoded password (`qweasd123456`) and ignores file content. A background watcher (`StartWatcher`) then scans this folder every 5 seconds. If it finds a new exe…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28674">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4219 – A flaw has been found in INDEX Conferences &amp; Exhibitions Organization YWF BPOF A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4219</guid>
    <pubDate>Mon, 16 Mar 2026 14:20:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4219</strong></p>
  <p>A flaw has been found in INDEX Conferences & Exhibitions Organization YWF BPOF APGCS App up to 1.0.2 on Android. Affected by this vulnerability is an unknown functionality of the file com/index/event/BuildConfig.java of the component ae.index.apgcs. Executing a manipulation of the argument ACCESS_KEY/HASH_KEY can lead to hard-coded credentials. The attack is restricted to local execution. The exp…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4216 – A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4216</guid>
    <pubDate>Mon, 16 Mar 2026 14:20:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4216</strong></p>
  <p>A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the component air.SmartLog.android. This manipulation causes hard-coded credentials. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor explains: "The function referenced in the report currently exists i…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-20031 – ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20031</guid>
    <pubDate>Mon, 16 Mar 2026 14:17:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-20031</strong></p>
  <p>ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid credentials by spoofing localhost requests. Attackers can exploit the EnvironmentUtil.getClientIp() method which treats IPv6 loopback address 0:0:0:0:0:0:0:1 as 127.0.0.1 and authenticates using the IP as username with hardcoded password 123456 to access…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-20026 – ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache To...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20026</guid>
    <pubDate>Mon, 16 Mar 2026 14:17:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-20026</strong></p>
  <p>ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives containing JSP applications and execute arbitrary code with SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3873 – Use of Hard-coded Credentials vulnerability in Avantra allows Accessing 
Functio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3873</guid>
    <pubDate>Fri, 13 Mar 2026 19:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3873</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Avantra allows Accessing  Functionality Not Properly Constrained by ACLs. This issue affects  Avantra: before 25.3.0.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28255 – A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28255</guid>
    <pubDate>Thu, 12 Mar 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28255</strong></p>
  <p>A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-59388 – A use of hard-coded password vulnerability has been reported to affect Hyper Dat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59388</guid>
    <pubDate>Thu, 12 Mar 2026 02:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-59388</strong></p>
  <p>A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access.  We have already fixed the vulnerability in the following version: Hyper Data Protector 2.3.1.455 and later</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-70041 – An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in osl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70041</guid>
    <pubDate>Wed, 11 Mar 2026 21:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-70041</strong></p>
  <p>An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24448 – Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24448</guid>
    <pubDate>Wed, 11 Mar 2026 06:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24448</strong></p>
  <p>Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70802 – Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70802</guid>
    <pubDate>Tue, 10 Mar 2026 21:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70802</strong></p>
  <p>Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70798 – Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70798</guid>
    <pubDate>Tue, 10 Mar 2026 21:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70798</strong></p>
  <p>Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13957 – CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause inf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13957</guid>
    <pubDate>Tue, 10 Mar 2026 18:17:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13957</strong></p>
  <p>CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29023 – Keygraph Shannon contains a hard-coded API key in its router configuration that,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29023</guid>
    <pubDate>Mon, 09 Mar 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29023</strong></p>
  <p>Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network attackers to authenticate using the publicly known static key. An attacker able to reach the router port can proxy requests through the Shannon instance using the victim’s configured upstream provider API credentials, resulting in unauthorized API usage…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28776 – International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28776</guid>
    <pubDate>Wed, 04 Mar 2026 08:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28776</strong></p>
  <p>International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can use these trivial, undocumented credentials to access the system via SSH. While initially dropped into a restricted shell, the attacker can trivially break out to achieve standard shell functionality.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-55021 – Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55021</guid>
    <pubDate>Tue, 03 Mar 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-55021</strong></p>
  <p>Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26985 – LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web app...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26985</guid>
    <pubDate>Wed, 25 Feb 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26985</strong></p>
  <p>LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Starting in version 24.0.0 and prior to versions 26.0.5, 27.0.2, and 28.0.0, an authenticated user with the appropriate authorization can read configuration files on the server by exploiting a path traversal vulnerability. Some of these fil…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67304 – In Ruckus Network Director (RND) &lt; 4.5.0.54, the OVA appliance contains hardcode...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67304</guid>
    <pubDate>Thu, 19 Feb 2026 20:25:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67304</strong></p>
  <p>In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network on TCP port 5432. An attacker can use the hardcoded credentials to authenticate remotely, gaining superuser access to the database. This allows creation of administrative users for…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-2702 – A security flaw has been discovered in Beetel 777VR1 up to 01.00.09. This issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2702</guid>
    <pubDate>Thu, 19 Feb 2026 07:17:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-2702</strong></p>
  <p>A security flaw has been discovered in Beetel 777VR1 up to 01.00.09. This issue affects some unknown processing of the component WPA2 PSK. Performing a manipulation results in hard-coded credentials. The attacker must have access to the local network to execute the attack. The complexity of an attack is rather high. The exploitability is assessed as difficult. The exploit has been released to the…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22769 – Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22769</guid>
    <pubDate>Tue, 17 Feb 2026 20:22:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22769</strong></p>
  <p>Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upg…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-23647 – Glory RBG-100 recycler systems using the ISPK-08 software component contain hard...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23647</guid>
    <pubDate>Tue, 17 Feb 2026 17:21:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23647</strong></p>
  <p>Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user accounts, including accounts with administrative privileges, were found to have fixed, embedded passwords. An attacker with network access to exposed services such as SSH may authenticate using thes…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2616 – A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2616</guid>
    <pubDate>Tue, 17 Feb 2026 15:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2616</strong></p>
  <p>A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. It is advisable to modify the configuration settings. The vendor was contacte…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25322 – Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25322</guid>
    <pubDate>Thu, 12 Feb 2026 23:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25322</strong></p>
  <p>Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' in the hidden form input fields.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37135 – AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37135</guid>
    <pubDate>Sat, 07 Feb 2026 00:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37135</strong></p>
  <p>AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-69971 – FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-hel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69971</guid>
    <pubDate>Tue, 03 Feb 2026 18:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-69971</strong></p>
  <p>FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin tokens and bypass authentication to gain full administrative access.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1610 – A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1610</guid>
    <pubDate>Thu, 29 Jan 2026 19:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1610</strong></p>
  <p>A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipulation results in hard-coded credentials. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been made public and coul…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-40537 – SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40537</guid>
    <pubDate>Wed, 28 Jan 2026 08:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-40537</strong></p>
  <p>SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24840 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24840</guid>
    <pubDate>Wed, 28 Jan 2026 01:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24840</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.com/install.sh, line 154) uses a hardcoded password when creating the database container. This means that nearly all Dokploy installations use the same database credentials and could be compromised. Version 0.26.6 contai…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-59091 – Multiple hardcoded credentials have been identified, which are allowed to sign-i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59091</guid>
    <pubDate>Mon, 26 Jan 2026 10:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-59091</strong></p>
  <p>Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This information, among other things, is used to graphically visualize open doors and alerts. However, controlling the Access Managers via this interface is also possi…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58744 – Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58744</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58744</strong></p>
  <p>Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in    Milner ImageDirector Capture on Windows allows decryption of document archive files using credentials decrypted with hard-coded application encryption key.  This issue affects ImageDirector Capture: from 7.0.9.0 before 7.6.3.25808.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14115 – IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14115</guid>
    <pubDate>Tue, 20 Jan 2026 15:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14115</strong></p>
  <p>IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBM® Sterling Connect:Direct for UNIX contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1221 – PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS  has a Use of Hard...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1221</guid>
    <pubDate>Tue, 20 Jan 2026 07:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1221</strong></p>
  <p>PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS  has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to the database using hardcoded database credentials stored in the firmware.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-69426 – The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69426</guid>
    <pubDate>Fri, 09 Jan 2026 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-69426</strong></p>
  <p>The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables SCP and pseudo-TTY allocation, an attacker can authenticate using the hardcoded credentials and establish SSH local port f…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-7072 – The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credential...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7072</guid>
    <pubDate>Fri, 09 Jan 2026 12:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-7072</strong></p>
  <p>The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an unauthenticated remote attacker could use to execute commands with root privileges. This vulnerability has been fixed in firmware version: 1.00.67 for CG3000TC and 1.00.27 for CG3000T.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68718 – KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68718</guid>
    <pubDate>Thu, 08 Jan 2026 21:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68718</strong></p>
  <p>KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root credentials (root:12345678). The administrator cannot disable these services or change the hardcoded password. (Changing the management GUI password does not affect SSH/TELNET authentication.) Any LAN-adjacent attacker can trivially log in with root privileges.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25291 – INIM Electronics Smartliving SmartLAN/G/SI &lt;=6.x contains hard-coded credentials...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25291</guid>
    <pubDate>Thu, 08 Jan 2026 00:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25291</strong></p>
  <p>INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47744 – Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47744</guid>
    <pubDate>Wed, 31 Dec 2025 19:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47744</strong></p>
  <p>Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes root access. Attackers can exploit the static 'Chameleon' password to gain remote root access via Telnet or SSH on affected devices.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15371 – A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, No...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15371</guid>
    <pubDate>Wed, 31 Dec 2025 01:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15371</strong></p>
  <p>A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. Affected is an unknown function of the component Shadow File. Such manipulation with the input Fireitup leads to hard-coded credentials. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-53983 – Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53983</guid>
    <pubDate>Tue, 30 Dec 2025 23:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-53983</strong></p>
  <p>Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-50696 – SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50696</guid>
    <pubDate>Tue, 30 Dec 2025 23:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-50696</strong></p>
  <p>SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-33222 – NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33222</guid>
    <pubDate>Tue, 23 Dec 2025 17:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-33222</strong></p>
  <p>NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and data tampering.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65857 – An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.00080...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65857</guid>
    <pubDate>Mon, 22 Dec 2025 22:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65857</strong></p>
  <p>An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7358 – Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7358</guid>
    <pubDate>Thu, 18 Dec 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7358</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse.This issue affects SoliClub: before 5.3.7.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1029 – Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1029</guid>
    <pubDate>Thu, 18 Dec 2025 15:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1029</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. SoliClub allows Read Sensitive Constants Within an Executable.This issue affects SoliClub: from 5.2.4 before 5.3.7.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67809 – An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67809</guid>
    <pubDate>Mon, 15 Dec 2025 20:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67809</strong></p>
  <p>An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-47731 – Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47731</guid>
    <pubDate>Tue, 09 Dec 2025 21:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-47731</strong></p>
  <p>Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocumented page. Attackers can exploit the hidden endpoint by using the hard-coded password 'Selea781830' to enable configuration upload and overwrite device settings.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41696 – An attacker can use an undocumented UART port on the PCB as a side-channel with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41696</guid>
    <pubDate>Tue, 09 Dec 2025 16:17:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41696</strong></p>
  <p>An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14126 – A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14126</guid>
    <pubDate>Sat, 06 Dec 2025 10:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14126</strong></p>
  <p>A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the component Web Interface. Such manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65730 – Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65730</guid>
    <pubDate>Fri, 05 Dec 2025 16:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65730</strong></p>
  <p>Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens used for authentication.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66237 – DCIM dcTrack platforms utilize default and hard-coded credentials for access. An...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66237</guid>
    <pubDate>Thu, 04 Dec 2025 21:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66237</strong></p>
  <p>DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system commands on the host.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-29268 – ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29268</guid>
    <pubDate>Thu, 04 Dec 2025 20:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-29268</strong></p>
  <p>ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64778 – NMIS/BioDose software V22.02 and previous versions contain executable binaries w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64778</guid>
    <pubDate>Tue, 02 Dec 2025 21:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64778</strong></p>
  <p>NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application and database.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-25126 – Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25126</guid>
    <pubDate>Mon, 24 Nov 2025 21:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-25126</strong></p>
  <p>Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and an OS command injection flaw in its configuration services. The web/API interface accepts HTTP/XML requests authenticated with a fixed vendor credential string and passes user-controlled fields into shell execution contexts without proper argument s…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59669 – A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiW...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59669</guid>
    <pubDate>Tue, 18 Nov 2025 17:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59669</strong></p>
  <p>A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker with shell access to the device to connect to redis service and access its data</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31649 – A hard-coded password vulnerability exists in the ControlVault WBDI Driver funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31649</guid>
    <pubDate>Mon, 17 Nov 2025 23:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31649</strong></p>
  <p>A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to execute priviledged operation. An attacker can issue an api call to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13252 – A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13252</guid>
    <pubDate>Sun, 16 Nov 2025 23:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13252</strong></p>
  <p>A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Affected by this issue is some unknown functionality of the component RSA/OAuth2/Database. The manipulation results in hard-coded credentials. The attack can be executed remotely. The exploit has been made public and could be used. This product implements a rolling release for ongoing de…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64308 – The Brightpick Mission Control web application exposes hardcoded credentials in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64308</guid>
    <pubDate>Sat, 15 Nov 2025 00:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64308</strong></p>
  <p>The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-523</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12676 – The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12676</guid>
    <pubDate>Wed, 05 Nov 2025 08:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12676</strong></p>
  <p>The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5. This is due to the plugin using a hardcoded password for authentication in the QueryControllerAdmin::authenticated function. This makes it possible for unauthenticated attackers to create and sync products.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34501 – Deck Mate 2 is distributed with static, hard-coded credentials for the root shel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34501</guid>
    <pubDate>Mon, 03 Nov 2025 22:18:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34501</strong></p>
  <p>Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HTTP, Telnet, SMB, X11) are enabled by default. If an attacker can reach these interfaces - most often through local or near-local access such as connecting to the USB or Ethernet ports beneath the table - the built-in credentials permit administrative…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62777 – Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62777</guid>
    <pubDate>Tue, 28 Oct 2025 05:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62777</strong></p>
  <p>Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to log in to the affected device via Telnet and execute arbitrary commands.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-56801 – The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56801</guid>
    <pubDate>Tue, 21 Oct 2025 19:21:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-56801</strong></p>
  <p>The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data. NOTE: the Supplier's position is that material is not hardcoded and is instead randomly generated on each installation of the application.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10639 – The WorkExaminer Professional server installation comes with an FTP server that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10639</guid>
    <pubDate>Tue, 21 Oct 2025 12:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10639</strong></p>
  <p>The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with network access to this port can use weak hardcoded credentials to login to the FTP server and modify or read data, log files and gain remote code execution as NT Authority\SYSTEM on the server by exchanging accessible service binaries in the WorkEx…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-6950 – An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s net...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6950</guid>
    <pubDate>Fri, 17 Oct 2025 04:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-6950</strong></p>
  <p>An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated attacker to forge valid tokens, thereby bypassing authentication controls and impersonating any user. Exploitation of this vulne…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60639 – Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60639</guid>
    <pubDate>Thu, 16 Oct 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60639</strong></p>
  <p>Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-10850 – The Felan Framework plugin for WordPress is vulnerable to improper authenticatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10850</guid>
    <pubDate>Thu, 16 Oct 2025 07:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-10850</strong></p>
  <p>The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password in the 'fb_ajax_login_or_register' function and in the 'google_ajax_login_or_register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they registered with facebook or google s…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-11666 – A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11666</guid>
    <pubDate>Mon, 13 Oct 2025 07:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-11666</strong></p>
  <p>A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to use of hard-coded password. The attack can only be executed locally. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36087 – IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36087</guid>
    <pubDate>Mon, 13 Oct 2025 01:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36087</strong></p>
  <p>IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11649 – A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. The affected elem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11649</guid>
    <pubDate>Sun, 12 Oct 2025 23:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11649</strong></p>
  <p>A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the component Root Account Handler. Performing manipulation results in use of hard-coded password. The attack must be initiated from a local position. The attack is considered to have high complexity. The exploitability is described as difficult. The exploit has been made public and could…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11649">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
