Filtered by CWE-798
Total 1269 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-40111 1 Totolink 2 A3002r, A3002r Firmware 2024-08-03 9.8 Critical
In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.
CVE-2022-40259 1 Ami 1 Megarac Sp-x 2024-08-03 8.3 High
MegaRAC Default Credentials Vulnerability
CVE-2022-40242 1 Ami 1 Megarac Sp-x 2024-08-03 7.5 High
MegaRAC Default Credentials Vulnerability
CVE-2022-39989 1 Fighting Cock Information System Project 1 Fighting Cock Information System 2024-08-03 9.8 Critical
An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials.
CVE-2022-39273 1 Flyte 1 Flyteadmin 2024-08-03 4.8 Medium
FlyteAdmin is the control plane for the data processing platform Flyte. Users who enable the default Flyte’s authorization server without changing the default clientid hashes will be exposed to the public internet. In an effort to make enabling authentication easier for Flyte administrators, the default configuration for Flyte Admin allows access for Flyte Propeller even after turning on authentication via a hardcoded hashed password. This password is also set on the default Flyte Propeller configmap in the various Flyte Helm charts. Users who enable auth but do not override this setting in Flyte Admin’s configuration may unbeknownst to them be allowing public traffic in by way of this default password with attackers effectively impersonating propeller. This only applies to users who have not specified the ExternalAuthorizationServer setting. Usage of an external auth server automatically turns off this default configuration and are not susceptible to this vulnerability. This issue has been addressed in version 1.1.44. Users should manually set the staticClients in the selfAuthServer section of their configuration if they intend to rely on Admin’s internal auth server. Again, users who use an external auth server are automatically protected from this vulnerability.
CVE-2022-39185 1 Exfo 2 Bv-10, Bv-10 Firmware 2024-08-03 9.8 Critical
EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user.
CVE-2022-38823 1 Totolink 2 T6, T6 Firmware 2024-08-03 9.8 Critical
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.
CVE-2022-38394 1 Allied-telesis 2 Centrecom Ar260s, Centrecom Ar260s Firmware 2024-08-03 9.8 Critical
Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attacker to execute an arbitrary OS command.
CVE-2022-38337 1 Mobatek 1 Mobaxterm 2024-08-03 9.1 Critical
When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of Service (DoS) for the user if services like fail2ban are used.
CVE-2022-37832 1 Mutiny 1 Mutiny 2024-08-03 9.8 Critical
Mutiny 7.2.0-10788 suffers from Hardcoded root password.
CVE-2022-37857 1 Hauk Project 1 Hauk 2024-08-03 7.5 High
bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.
CVE-2022-37841 1 Totolink 2 A860r, A860r Firmware 2024-08-03 7.5 High
In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.
CVE-2022-37710 1 Pattersondental 1 Eaglesoft 2024-08-03 7.8 High
Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt that are hardcoded into a DLL or EXE file.
CVE-2022-37255 1 Tp-link 2 Tapo C310, Tapo C310 Firmware 2024-08-03 7.5 High
TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603.
CVE-2022-36952 1 Veritas 1 Netbackup 2024-08-03 8.4 High
In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
CVE-2022-36925 1 Zoom 1 Rooms 2024-08-03 4.4 Medium
Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used for IPC between the Zoom Rooms daemon service and the Zoom Rooms client was generated using parameters that could be obtained by a local low-privileged application. That key can then be used to interact with the daemon service to execute privileged functions and cause a local denial of service.
CVE-2022-36672 1 Xxyopen 1 Novel-plus 2024-08-03 9.8 Critical
Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.
CVE-2022-36612 1 Totolink 2 A950rg, A950rg Firmware 2024-08-03 7.8 High
TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2022-36615 1 Totolink 2 A3000ru, A3000ru Firmware 2024-08-03 7.8 High
TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2022-36611 1 Totolink 2 A800r, A800r Firmware 2024-08-03 7.8 High
TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.