CWE-259: Use of Hard-coded Password
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
168 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-8730 — Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
- CVE-2025-11126 — Apeman ID71 system.ini hard-coded credentials
- CVE-2024-32741 — A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded pa
- CVE-2025-1100 — A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allow
- CVE-2025-20286 — ISE on AWS Static Credential
- CVE-2024-4708 — mySCADA myPRO Use of Hard-coded Password
- CVE-2024-43423 — Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE Use of Hard-coded Password
- CVE-2024-34025 — CyberPower PowerPanel business Use of Hard-coded Password
- CVE-2024-33625 — CyberPower PowerPanel business Use of Hard-coded Password
- CVE-2026-25753 — PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)
- CVE-2024-4996 — Hardcoded Password in Wapro ERP Desktop
- CVE-2024-20412 — A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series c
- CVE-2024-1228 — Hardcoded password in Eurosoft Przychodnia
- CVE-2026-1610 — Tenda AX12 Pro V2 Telnet Service hard-coded credentials
- CVE-2026-4475 — Yi Technology YI Home Camera ipc hard-coded credentials
- CVE-2026-2616 — Beetel 777VR1 Web Management hard-coded credentials
- CVE-2025-44955 — RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.
- CVE-2025-2402 — Hard-coded password for object store of KNIME Business Hub
- CVE-2025-14126 — TOZED ZLT M30S/ZLT M30S PRO Web hard-coded credentials
- CVE-2025-58081 — Use of hard-coded password issue/vulnerability in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allo
Recently published
- CVE-2026-86673 — ningzichun Student Management System Database Connection database.php mysqli_connect hard-coded credentials
- CVE-2026-86276 — SourceCodester Syllabus-Aligned Learning Management & Examination System db.php hard-coded credentials
- CVE-2026-86150 — Tenda CP3 hostapd hard-coded credentials
- CVE-2026-70403 — XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log i
- CVE-2026-82808 — Inbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker.production-esm.js hard-coded credentials
- CVE-2026-78062 — vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials
- CVE-2026-23933 — Hardcoded session key in Zabbix 7.4
- CVE-2026-19901 — LB-LINK X-PRO easycwmp hard-coded credentials
- CVE-2026-19900 — LB-LINK X-PRO shadow hard-coded credentials
- CVE-2026-19750 — Tenda CH/CP/TX3 SSH hard-coded password
- CVE-2026-20316 — Cisco Secure Firewall Management Center Software Static Credential Vulnerability
- CVE-2026-11552 — SourceCodester Onlne Examination & Learning Management System import_users.php hard-coded password
- CVE-2026-11515 — SourceCodester Barangay Resident Profiling and Information Management System Password Reset passsword_reset.php hard-coded password
- CVE-2026-7251 — Eppendorf BioFlo 320 Use of hard-coded password
- CVE-2026-8032 — PicoTronica e-Clinic Healthcare System ECHS echs.js hard-coded credentials
- CVE-2026-7579 — AstrBotDevs AstrBot Dashboard auth.py hard-coded credentials
- CVE-2026-6610 — liangliangyy DjangoBlog Setting settings.py hard-coded credentials
- CVE-2026-6578 — liangliangyy DjangoBlog Setting settings.py hard-coded credentials
- CVE-2026-6574 — osuuu LightPicture API Upload Endpoint lp.sql hard-coded credentials
- CVE-2025-57175 — Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password.