#Hard-Coded Credentials
All CosmicBytez Labs articles tagged #Hard-Coded Credentials, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-65113: Hard-Coded Credentials Flaw in NVIDIA Infrastructure Controller for Linux
Critical CVSS 9.8 flaw in NVIDIA Infrastructure Controller for Linux lets attackers exploit hard-coded credentials for full system compromise.
- News
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
CVE-2026-28326 (CVSS 8.8) is a hard-coded static key in SolarWinds Access Rights Manager, patched in ARM 2026.2.1.
- Security
Digital Watchdog VMAX Root FTP Credentials Baked In
CVE-2026-66890 (CVSS 9.6) hard-codes root-level FTP credentials into Digital Watchdog VMAX DVR/NVR firmware, enabling remote root file access.
- Security
Hard-Coded SSH Credentials Expose Lightstar SmartIT Desktop Manager
CVE-2026-85146 lets unauthenticated attackers pull SSH service credentials straight from SmartIT Desktop Manager's source code to access agent hosts.
- Security
Hard-Coded Fixed Password in SmartIT Desktop Manager Enables Host Takeover
CVE-2026-85148 lets unauthenticated attackers use a fixed, embedded password to remotely access hosts managed by Lightstar's SmartIT Desktop Manager.
- Security
CVE-2026-50208: TLS Bypass and Hard-Coded DES Keys Enable MITM Attacks
A critical CVSS 9.4 vulnerability disables TLS certificate validation via TrustAllCerts routines and combines this with hard-coded DES symmetric encryption…
- Security
CVE-2026-49191: M3WebServer Hard-Coded API Keys Exposed via Error Pages
A critical CVSS 9.8 vulnerability in M3WebServer hard-codes backend API keys in the production build. Attackers intercept them through verbose error handling…
- Security
Dell ECS and ObjectScale: Hard-Coded Credentials
A critical CVSS 9.8 hard-coded credentials vulnerability in Dell ECS and ObjectScale allows unauthenticated local attackers to gain full filesystem access...