On this page
CWE-798: Use of Hard-coded Credentials
Weakness Summary
The product contains hard-coded credentials, such as a password or cryptographic key.
- Canonical source: MITRE CWE-798 (opens in a new tab)
- Published Atomicorp CVE observations: 12
- Distinct affected products in those observations: 12
- Active Atomicorp rules associated with this weakness: 38
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2012-5686 | ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset | zpanel | Attack Blocked by Atomicorp | 340016 , 340017 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 360147 , 360148 , 390704 |
| CVE-2014-9614 | Netsweeper 4.0.5 - Default Weak Account | netsweeper | Attack Blocked by Atomicorp | 392301 |
| CVE-2015-4667 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | Attack Blocked by Atomicorp | 320464 , 320465 , 333141 , 340023 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 347198 , 350148 , 390726 , 392301 , 392647 , 392648 |
| CVE-2016-5678 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | nvrmini 2 | Attack Blocked by Atomicorp | 392301 |
| CVE-2017-7462 | Intellinet NFC-30IR Camera - Multiple Vulnerabilities | nfc-30ir firmware | Attack Blocked by Atomicorp | 330925 , 344360 , 347009 |
| CVE-2019-1935 | Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities | integrated management controller supervisor | Attack Blocked by Atomicorp | 344362 , 344363 , 344370 , 345493 , 350147 , 360151 , 390724 , 390727 , 392301 , 392648 |
| CVE-2022-34045 | WAVLINK WN530HG4 - Improper Access Control | wl-wn530hg4 firmware | Attack Blocked by Atomicorp | 390716 |
| CVE-2023-22463 | KubePi JwtSigKey - Admin Authentication Bypass | kubepi | Attack Blocked by Atomicorp | 392301 |
| CVE-2024-3408 | D-Tale 3.10.0 - 3.15.1 - Authentication Bypass & Remote Code Execution | dtale | Attack Blocked by Atomicorp | 340087 , 340095 |
| CVE-2026-44825 | Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials | solr | Attack Blocked by Atomicorp | 330925 |
| CVE-2024-7332 | TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password Vulnerability | cp450 firmware | Attack Blocked by Atomicorp | 390716 |
| CVE-2026-19900 | LB-LINK Routers - Unauthenticated Command Injection | bl-wr9000 firmware | Attack Blocked by Atomicorp | 390904 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 320464 | Active | disruptive (deny) |
| 320465 | Active | disruptive (deny) |
| 330925 | Active | disruptive (deny) |
| 333141 | Active | disruptive (deny) |
| 340016 | Active | disruptive (deny) |
| 340017 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340087 | Active | disruptive (deny) |
| 340095 | Active | disruptive (deny) |
| 340099 | Active | disruptive (deny) |
| 340147 | Active | disruptive (deny) |
| 340148 | Active | disruptive (deny) |
| 341099 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 342259 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344362 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 345493 | Active | non-disruptive (pass) |
| 346755 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 347198 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 350148 | Active | disruptive (deny) |
| 360147 | Active | disruptive (deny) |
| 360148 | Active | disruptive (deny) |
| 360151 | Active | disruptive (deny) |
| 390704 | Active | disruptive (deny) |
| 390716 | Active | disruptive (deny) |
| 390724 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 390727 | Active | disruptive (deny) |
| 390904 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 392648 | Active | disruptive (deny) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:
CAPEC-191 (opens in a new tab) , CAPEC-70 (opens in a new tab)