目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-321 使用硬编码的密码学密钥 类漏洞列表 319

CWE-321 使用硬编码的密码学密钥 类弱点 319 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-321 指软件在代码中硬编码了不可更改的加密密钥。攻击者通过逆向工程提取该密钥,即可解密受保护数据或伪造合法通信,严重破坏机密性与完整性。开发者应避免此类做法,改用动态密钥管理机制,如从安全密钥库、环境变量或硬件安全模块中运行时获取密钥,确保密钥可轮换且不与源代码一同发布。

MITRE CWE 官方描述
CWE:CWE-321 使用硬编码的加密密钥(Use of Hard-coded Cryptographic Key) 英文:The product uses a hard-coded, unchangeable cryptographic key. 译文:该产品使用了硬编码且不可更改的加密密钥(cryptographic key)。
常见影响 (1)
Access Control Bypass Protection Mechanism, Gain Privileges or Assume Identity, Read Application Data
If hard-coded cryptographic keys are used, it is almost certain that malicious users will gain access through the account in question. The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
缓解措施 (1)
Architecture and Design Prevention schemes mirror that of hard-coded password storage.
代码示例 (2)
The following code examples attempt to verify a password using a hard-coded cryptographic key.
int VerifyAdmin(char *password) { if (strcmp(password,"68af404b513073584c4b6f22b6c63e6b")) { printf("Incorrect Password!\n"); return(0); } printf("Entering Diagnostic Mode...\n"); return(1); }
Bad · C
public boolean VerifyAdmin(String password) { if (password.equals("68af404b513073584c4b6f22b6c63e6b")) { System.out.println("Entering Diagnostic Mode..."); return true; } System.out.println("Incorrect Password!"); return false;
Bad · Java
In 2022, the OT:ICEFALL study examined products by 10 different Operational Technology (OT) vendors. The researchers reported 56 vulnerabilities and said that the products were "insecure by design" [REF-1283]. If exploited, these vulnerabilities often allowed adversaries to change how the products operated, ranging from denial of service to changing the code that the products executed. Since these…
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-63423 Lenovo Accessories and Display Manager 加密问题漏洞 — Accessories and Display Manager 7.8 High 2026-08-13
CVE-2026-34635 Adobe ColdFusion 加密问题漏洞 — ColdFusion 2025 8.4 High 2026-08-11
CVE-2026-57262 Siemens LOGO! Soft Comfort 加密问题漏洞 — LOGO! Soft Comfort 6.8 Medium 2026-08-11
CVE-2026-66763 SAP BusinessObjects Business Intelligence Platform 加密问题漏洞 — SAP BusinessObjects Business Intelligence Platform (Central Management Server) 7.9 High 2026-08-11
CVE-2025-30239 TP-Link HX510 加密问题漏洞 — HB810(US2) V1.0/1.6/2.0/2.6 8.5 High 2026-08-10
CVE-2026-54218 Tobit Laboratories AG TeamDavid WebBox 加密问题漏洞 — TeamDavid 8.8 High 2026-08-07
CVE-2026-49008 ZTE F689 加密问题漏洞 — F689 6.5 Medium 2026-08-07
CVE-2026-49006 ZTE F689 加密问题漏洞 — F689 5.3 Medium 2026-08-07
CVE-2026-18411 Acrisure KARR BT 加密问题漏洞 — KARR BT 8.1 High 2026-08-05
CVE-2026-14804 Bilin HUMANIST Digital Human Resources 加密问题漏洞 — HUMANIST Digital Human Resources 9.1 Critical 2026-08-04
CVE-2026-18754 GeoVision GV-AS1620 加密问题漏洞 — GV-AS1620 (GV-Cloud) 9.1 Critical 2026-08-04
CVE-2026-18753 GeoVision GV-AS1620 加密问题漏洞 — GV-AS1620 (AS-Manager) 9.1 Critical 2026-08-04
CVE-2025-15627 TP-Link Omada 加密问题漏洞 — Omada Gateways 6.9 Medium 2026-08-03
CVE-2026-5846 watchfire BC550 加密问题漏洞 — BC550 5.7 Medium 2026-07-30
CVE-2026-54363 Gladinet CentreStack 加密问题漏洞 — CentreStack 9.1 Critical 2026-07-30
CVE-2026-14932 Progress Software Progress Telerik UI for AJAX 加密问题漏洞 — Telerik UI for ASP.NET AJAX 6.5 Medium 2026-07-22
CVE-2026-13184 Progress Software Progress Telerik UI for AJAX 加密问题漏洞 — Telerik UI for ASP.NET AJAX 7.5 High 2026-07-22
CVE-2026-47410 MervinPraison PraisonAI 加密问题漏洞 — praisonai-platform 9.8 Critical 2026-07-21
CVE-2026-9770 TP-Link Systems Inc Kasa EC71 v4 加密问题漏洞 — Kasa EC71 v4 - - 2026-07-15
CVE-2026-56271 FlowiseAI Flowise 加密问题漏洞 — Flowise 9.8 Critical 2026-07-12
CVE-2026-57172 DataEase 加密问题漏洞 — dataease - - 2026-07-07
CVE-2026-54833 Dev Kabir Enable CORS 加密问题漏洞 — Enable CORS 7.4 High 2026-06-26
CVE-2026-9220 Shenzhen i365-Tech Setracker2 Parental Control App 加密问题漏洞 — Setracker2 Parental Control App (Android) package com.tgelec.setracker 7.5 High 2026-06-25
CVE-2026-35019 NetComm Wireless NF20MESH 加密问题漏洞 — NF20MESH 8.1 High 2026-06-23
CVE-2026-9260 Canon EOS Network Setting Tool 加密问题漏洞 — EOS Network Setting Tool for Windows 6.2 Medium 2026-06-15
CVE-2026-34029 Wertheim SafeController Software for VAULT ROOMS 加密问题漏洞 — Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) - - 2026-06-15
CVE-2026-34022 Wertheim SafeController Family 65000 Hardware for VAULT ROOMS 加密问题漏洞 — Wertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller) - - 2026-06-15
CVE-2026-28742 Naxclow Smart Doorbell X3 加密问题漏洞 — Smart Doorbell X3 9.8 Critical 2026-06-12
CVE-2026-50091 Aqara Home Android 加密问题漏洞 — com.lumiunited.aqarahome 9.1 Critical 2026-06-12
CVE-2026-11505 GL.iNet多款产品 加密问题漏洞 — A1300 5.0 Medium 2026-06-08

CWE-321(使用硬编码的密码学密钥) 是常见的弱点类别,本平台收录该类弱点关联的 319 条 CVE 漏洞。