BaseDraftTop 25 #22
CWE-798Use of Hard-coded Credentials
Category: auth
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Common consequences· 2
- Access Control — Bypass Protection Mechanism
- Integrity / Confidentiality / Availability / Access Control / Other — Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands, Other
Potential mitigations· 5
- [Architecture and Design]
- [Architecture and Design]For inbound authentication: Rather than hard-code a default username and password, key, or other authentication credentials for first time logins, utilize a "first login" mode that requires the user to enter a unique strong password or key.
- [Architecture and Design]If the product must contain hard-coded credentials or they cannot be removed, perform access control checks and limit which entities can access the feature that requires the hard-coded credentials. For example, a feature might only be enabled through the system console instead of through a network connection.
- [Architecture and Design]
- [Architecture and Design]
Related CAPEC attack patterns· 2
References
Exploits (incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Read Sensitive Constants Within an Executablecapec-191 | 100% | live |
| AttackPattern | Try Common or Default Usernames and Passwordscapec-70 | 100% | live |
Compliance frameworks addressing this (incoming)30
| Type | Target | Confidence | Tier |
|---|---|---|---|
| ComplianceControl | iso27001-a.8.5 | 100% | live |
| ComplianceControl | dora-art10 | 100% | live |
| ComplianceControl | ai_act-art15 | 100% | live |
| ComplianceControl | dora-art6 | 100% | live |
| ComplianceControl | iso27001-a.8.16 | 100% | live |
| ComplianceControl | tiber_eu-testing | 100% | live |
| ComplianceControl | cis_v8-6 | 100% | live |
| ComplianceControl | cis_v8-4 | 100% | live |
| ComplianceControl | nis2-art21g | 100% | live |
| ComplianceControl | nis2-art21j | 100% | live |
| ComplianceControl | iso27001-a.8.2 | 100% | live |
| ComplianceControl | dora-art24 | 100% | live |
| ComplianceControl | dora-art11 | 100% | live |
| ComplianceControl | pci_dss_v4-r12 | 100% | live |
| ComplianceControl | ai_act-art9 | 100% | live |
| ComplianceControl | dora-art25 | 100% | live |
| ComplianceControl | gdpr-art32 | 100% | live |
| ComplianceControl | dora-art5 | 100% | live |
| ComplianceControl | nist_csf-rc | 100% | live |
| ComplianceControl | owasp_llm_top10-llm04 | 100% | live |
| ComplianceControl | pci_dss_v4-r5 | 100% | live |
| ComplianceControl | iso27001-a.8.21 | 100% | live |
| ComplianceControl | tiber_eu-closure | 100% | live |
| ComplianceControl | nist_csf-rs | 100% | live |
| ComplianceControl | dora-art12 | 100% | live |
| ComplianceControl | pci_dss_v4-r7 | 100% | live |
| ComplianceControl | owasp_llm_top10-llm07 | 100% | live |
| ComplianceControl | gdpr-art34 | 100% | live |
| ComplianceControl | dora-art17 | 100% | live |
| ComplianceControl | pci_dss_v4-r8 | 100% | live |
(incoming)118
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-10639cve-2025-10639 | 0% | live |
| Vulnerability | CVE-2025-10681cve-2025-10681 | 0% | live |
| Vulnerability | CVE-2025-10850cve-2025-10850 | 0% | live |
| Vulnerability | CVE-2025-11126cve-2025-11126 | 0% | live |
| Vulnerability | CVE-2025-1143cve-2025-1143 | 0% | live |
| Vulnerability | CVE-2025-11643cve-2025-11643 | 0% | live |
| Vulnerability | CVE-2025-1242cve-2025-1242 | 0% | live |
| Vulnerability | CVE-2025-1393cve-2025-1393 | 0% | live |
| Vulnerability | CVE-2025-14096cve-2025-14096 | 0% | live |
| Vulnerability | CVE-2025-14115cve-2025-14115 | 0% | live |
| Vulnerability | CVE-2025-14126cve-2025-14126 | 0% | live |
| Vulnerability | Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerabilitycve-2025-14611 | 0% | live |
| Vulnerability | CVE-2025-14923cve-2025-14923 | 0% | live |
| Vulnerability | CVE-2025-15107cve-2025-15107 | 0% | live |
| Vulnerability | CVE-2025-20188cve-2025-20188 | 0% | live |
| Vulnerability | CVE-2025-20309cve-2025-20309 | 0% | live |
| Vulnerability | CVE-2025-2322cve-2025-2322 | 0% | live |
| Vulnerability | CVE-2025-2538cve-2025-2538 | 0% | live |
| Vulnerability | CVE-2025-25570cve-2025-25570 | 0% | live |
| Vulnerability | CVE-2025-26410cve-2025-26410 | 0% | live |
| Vulnerability | CVE-2025-27255cve-2025-27255 | 0% | live |
| Vulnerability | CVE-2025-27643cve-2025-27643 | 0% | live |
| Vulnerability | CVE-2025-2765cve-2025-2765 | 0% | live |
| Vulnerability | CVE-2025-28230cve-2025-28230 | 0% | live |
| Vulnerability | CVE-2025-28388cve-2025-28388 | 0% | live |
| Vulnerability | CVE-2025-29268cve-2025-29268 | 0% | live |
| Vulnerability | CVE-2025-30113cve-2025-30113 | 0% | live |
| Vulnerability | CVE-2025-30122cve-2025-30122 | 0% | live |
| Vulnerability | CVE-2025-30123cve-2025-30123 | 0% | live |
| Vulnerability | CVE-2025-30125cve-2025-30125 | 0% | live |
Showing top 30 of 118 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.