目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-321 使用硬编码的密码学密钥 类漏洞列表 289

CWE-321 使用硬编码的密码学密钥 类弱点 289 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-321 指软件在代码中硬编码了不可更改的加密密钥。攻击者通过逆向工程提取该密钥,即可解密受保护数据或伪造合法通信,严重破坏机密性与完整性。开发者应避免此类做法,改用动态密钥管理机制,如从安全密钥库、环境变量或硬件安全模块中运行时获取密钥,确保密钥可轮换且不与源代码一同发布。

MITRE CWE 官方描述
CWE:CWE-321 使用硬编码的加密密钥(Use of Hard-coded Cryptographic Key) 英文:The product uses a hard-coded, unchangeable cryptographic key. 译文:该产品使用了硬编码且不可更改的加密密钥(cryptographic key)。
常见影响 (1)
Access ControlBypass Protection Mechanism, Gain Privileges or Assume Identity, Read Application Data
If hard-coded cryptographic keys are used, it is almost certain that malicious users will gain access through the account in question. The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
缓解措施 (1)
Architecture and DesignPrevention schemes mirror that of hard-coded password storage.
代码示例 (2)
The following code examples attempt to verify a password using a hard-coded cryptographic key.
int VerifyAdmin(char *password) { if (strcmp(password,"68af404b513073584c4b6f22b6c63e6b")) { printf("Incorrect Password!\n"); return(0); } printf("Entering Diagnostic Mode...\n"); return(1); }
Bad · C
public boolean VerifyAdmin(String password) { if (password.equals("68af404b513073584c4b6f22b6c63e6b")) { System.out.println("Entering Diagnostic Mode..."); return true; } System.out.println("Incorrect Password!"); return false;
Bad · Java
In 2022, the OT:ICEFALL study examined products by 10 different Operational Technology (OT) vendors. The researchers reported 56 vulnerabilities and said that the products were "insecure by design" [REF-1283]. If exploited, these vulnerabilities often allowed adversaries to change how the products operated, ranging from denial of service to changing the code that the products executed. Since these…
CVE ID标题CVSS风险等级Published
CVE-2026-63423 联想Lenovo Accessories and Display Manager for Windows提权漏洞 — Accessories and Display Manager 7.8 High2026-08-13
CVE-2026-34635 Adobe ColdFusion 加密问题漏洞 — ColdFusion 2025 8.4 High2026-08-11
CVE-2026-57262 Siemens LOGO! Soft Comfort < V9 AES密钥硬编码漏洞 — LOGO! Soft Comfort 6.8 Medium2026-08-11
CVE-2026-66763 SAP BusinessObjects 凭证泄露漏洞 — SAP BusinessObjects Business Intelligence Platform (Central Management Server) 7.9 High2026-08-11
CVE-2025-30239 TP-Link Aginet 多设备硬编码加密密钥导致敏感数据泄露漏洞 — HB810(US2) V1.0/1.6/2.0/2.6 8.5 High2026-08-10
CVE-2026-54218 Tobit Laboratories AG TeamDavid WebBox 加密问题漏洞 — TeamDavid 8.8 High2026-08-07
CVE-2026-49008 ZTE F689 加密问题漏洞 — F689 6.5 Medium2026-08-07
CVE-2026-49006 ZTE F689 加密问题漏洞 — F689 5.3 Medium2026-08-07
CVE-2026-18411 Acrisure KARR BT 加密问题漏洞 — KARR BT 8.1 High2026-08-05
CVE-2026-14804 Bilin HUMANIST Digital Human Resources 加密问题漏洞 — HUMANIST Digital Human Resources 9.1 Critical2026-08-04
CVE-2026-18754 GeoVision GV-AS1620 加密问题漏洞 — GV-AS1620 (GV-Cloud) 9.1 Critical2026-08-04
CVE-2026-18753 GeoVision GV-AS1620 加密问题漏洞 — GV-AS1620 (AS-Manager) 9.1 Critical2026-08-04
CVE-2025-15627 TP-Link Omada 加密问题漏洞 — Omada Gateways 6.9 Medium2026-08-03
CVE-2026-5846 watchfire BC550 加密问题漏洞 — BC550 5.7 Medium2026-07-30
CVE-2026-54363 Gladinet CentreStack 加密问题漏洞 — CentreStack 9.1 Critical2026-07-30
CVE-2026-14932 Progress Software Progress Telerik UI for AJAX 加密问题漏洞 — Telerik UI for ASP.NET AJAX 6.5 Medium2026-07-22
CVE-2026-13184 Progress Software Progress Telerik UI for AJAX 加密问题漏洞 — Telerik UI for ASP.NET AJAX 7.5 High2026-07-22
CVE-2026-47410 MervinPraison PraisonAI 加密问题漏洞 — praisonai-platform 9.8 Critical2026-07-21
CVE-2026-9770 TP-Link Systems Inc Kasa EC71 v4 加密问题漏洞 — Kasa EC71 v4--2026-07-15
CVE-2026-56271 FlowiseAI Flowise 加密问题漏洞 — Flowise 9.8 Critical2026-07-12
CVE-2026-57172 DataEase 加密问题漏洞 — dataease--2026-07-07
CVE-2026-54833 Dev Kabir Enable CORS 加密问题漏洞 — Enable CORS 7.4 High2026-06-26
CVE-2026-9220 Shenzhen i365-Tech Setracker2 Parental Control App 加密问题漏洞 — Setracker2 Parental Control App (Android) package com.tgelec.setracker 7.5 High2026-06-25
CVE-2026-35019 NetComm Wireless NF20MESH 加密问题漏洞 — NF20MESH 8.1 High2026-06-23
CVE-2026-9260 Canon EOS Network Setting Tool 加密问题漏洞 — EOS Network Setting Tool for Windows 6.2 Medium2026-06-15
CVE-2026-34029 Wertheim SafeController Software for VAULT ROOMS 加密问题漏洞 — Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)--2026-06-15
CVE-2026-34022 Wertheim SafeController Family 65000 Hardware for VAULT ROOMS 加密问题漏洞 — Wertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)--2026-06-15
CVE-2026-28742 Naxclow Smart Doorbell X3 加密问题漏洞 — Smart Doorbell X3 9.8 Critical2026-06-12
CVE-2026-50091 Aqara Home Android 加密问题漏洞 — com.lumiunited.aqarahome 9.1 Critical2026-06-12
CVE-2026-11505 GL.iNet多款产品 加密问题漏洞 — A1300 5.0 Medium2026-06-08

CWE-321(使用硬编码的密码学密钥) 是常见的弱点类别,本平台收录该类弱点关联的 289 条 CVE 漏洞。