Total
1366 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-38117 | 1 Juiker | 1 Juiker | 2024-11-21 | N/A | 5.5 MEDIUM |
Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt users’ ciphertext and tamper with it. | |||||
CVE-2022-38116 | 1 Leyan | 1 Salary Management System | 2024-11-21 | N/A | 9.8 CRITICAL |
Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote attacker can access, modify system data or disrupt service. | |||||
CVE-2022-38069 | 1 Contechealth | 2 Cms8000, Cms8000 Firmware | 2024-11-21 | N/A | 4.3 MEDIUM |
Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters | |||||
CVE-2022-37857 | 1 Hauk Project | 1 Hauk | 2024-11-21 | N/A | 7.5 HIGH |
bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default. | |||||
CVE-2022-37841 | 1 Totolink | 2 A860r, A860r Firmware | 2024-11-21 | N/A | 7.5 HIGH |
In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample. | |||||
CVE-2022-36952 | 1 Veritas | 1 Netbackup | 2024-11-21 | N/A | 8.4 HIGH |
In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10. | |||||
CVE-2022-36925 | 1 Zoom | 1 Rooms | 2024-11-21 | N/A | 4.4 MEDIUM |
Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used for IPC between the Zoom Rooms daemon service and the Zoom Rooms client was generated using parameters that could be obtained by a local low-privileged application. That key can then be used to interact with the daemon service to execute privileged functions and cause a local denial of service. | |||||
CVE-2022-36672 | 1 Xxyopen | 1 Novel-plus | 2024-11-21 | N/A | 9.8 CRITICAL |
Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session. | |||||
CVE-2022-36616 | 1 Totolink | 2 A810r, A810r Firmware | 2024-11-21 | N/A | 7.8 HIGH |
TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | |||||
CVE-2022-36615 | 1 Totolink | 2 A3000ru, A3000ru Firmware | 2024-11-21 | N/A | 7.8 HIGH |
TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | |||||
CVE-2022-36614 | 1 Totolink | 2 A860r, A860r Firmware | 2024-11-21 | N/A | 7.8 HIGH |
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | |||||
CVE-2022-36613 | 1 Totolink | 2 N600r, N600r Firmware | 2024-11-21 | N/A | 7.8 HIGH |
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | |||||
CVE-2022-36612 | 1 Totolink | 2 A950rg, A950rg Firmware | 2024-11-21 | N/A | 7.8 HIGH |
TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | |||||
CVE-2022-36611 | 1 Totolink | 2 A800r, A800r Firmware | 2024-11-21 | N/A | 7.8 HIGH |
TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | |||||
CVE-2022-36610 | 1 Totolink | 2 A720r, A720r Firmware | 2024-11-21 | N/A | 7.8 HIGH |
TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | |||||
CVE-2022-36560 | 1 Seiko-sol | 2 Skybridge Mb-a200, Skybridge Mb-a200 Firmware | 2024-11-21 | N/A | 9.8 CRITICAL |
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh. | |||||
CVE-2022-36558 | 1 Seiko-sol | 4 Skybridge Mb-a100, Skybridge Mb-a100 Firmware, Skybridge Mb-a110 and 1 more | 2024-11-21 | N/A | 9.8 CRITICAL |
Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg. | |||||
CVE-2022-36171 | 1 Mapgis | 1 Mapgis Igserver | 2024-11-21 | N/A | 8.1 HIGH |
MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion. | |||||
CVE-2022-36170 | 1 Mapgis | 1 Igserver | 2024-11-21 | N/A | 8.8 HIGH |
MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitrary file deletion. | |||||
CVE-2022-36159 | 1 Contec | 8 Fxa2000, Fxa2000 Firmware, Fxa3000 and 5 more | 2024-11-21 | N/A | 8.8 HIGH |
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware. |