CWE-321: Use of Hard-coded Cryptographic Key
The product uses a hard-coded, unchangeable cryptographic key.
315 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-30406 — Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
- CVE-2025-13316 — Hard-coded encryption keys in Twonky Server
- CVE-2025-34217 — Vasion Print (formerly PrinterLogic) Undocumented Hardcoded SSH Key
- CVE-2025-12599 — Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000)
- CVE-2026-25505 — Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication
- CVE-2026-22906 — Hardcoded Key Allows Credential Disclosure
- CVE-2025-8625 — Copypress Rest API 1.1 - 1.2 - Missing Configurable JWT Secret and File-Type Validation to Unauthenticated Remote Code Execution
- CVE-2025-41702 — egOS WebGUI Hard-Coded JWT Secret Enables Authentication Bypass
- CVE-2025-30206 — Dpanel's hard-coded JWT secret leads to remote code execution
- CVE-2025-15016 — Ragic|Enterprise Cloud Database - Hard-coded Cryptographic Key
- CVE-2026-26335 — Calero VeraSMART < 2022 R1 Static IIS Machine Keys Enable ViewState RCE
- CVE-2026-25894 — FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration
- CVE-2025-11899 — Flowring Technology|Agentflow - Use of Hard-coded Cryptographic Key
- CVE-2024-1631 — agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate`
- CVE-2025-44963 — RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded
- CVE-2025-30095 — VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the s
- CVE-2025-5353 — A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt s
- CVE-2025-26340 — A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.
- CVE-2025-22455 — A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt st
- CVE-2024-5722 — Logsign Unified SecOps Platform HTTP API Hard-coded Cryptographic Key Remote Code Execution Vulnerability
Recently published
- CVE-2026-87929 — MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key
- CVE-2026-79735 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-78486 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-78481 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-53939 — OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption
- CVE-2026-81821 — AVEVA Pipeline Integrity Monitor Use of hard-coded cryptographic key
- CVE-2026-80167 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-80057 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-78487 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-86241 — liufee FeehiCMS Cookie Validation main-local.php hard-coded key
- CVE-2026-80114 — PassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials Authentication Bypass via DirectIo64.sys
- CVE-2026-18330 — Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4
- CVE-2026-84483 — WWBN AVideo Unauthenticated Password Hash Oracle via encryptPass.json.php
- CVE-2026-74233 — Zbtlink MQWrt infosrvd Command Injection
- CVE-2026-24166 — NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-c
- CVE-2026-15469 — Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800
- CVE-2026-76847 — act 0.2.81 through 0.2.89 Missing Authorization in the Artifacts V4 Backend
- CVE-2026-76258 — Use of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure Gateway
- CVE-2026-64887 — Airwall - Hardcoded Secrets
- CVE-2026-17468 — IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution