PULSE
LIVE29signals / 24h
FEED
ransomunsafe reclama a DECK APP TECHNOLOGIES PTE. LTD · IN · Technologyransomthegentlemen reclama a CONTAC Ingenieros · CL · Professional Servicesransomthegentlemen reclama a RAK Construction · IN · Manufacturingransomthegentlemen reclama a Lancesoft India · IN · Technologyransomthegentlemen reclama a AIMS Group · GB · Otherransomthegentlemen reclama a AnMed · US · Healthcareransomthegentlemen reclama a NTU Alumni Club · SG · Educationransomthegentlemen reclama a Canopy Support Services · CA · Professional Servicesransomthegentlemen reclama a Mikel Coffee · MX · Retail & E-Commerceransomthegentlemen reclama a Hong Kong Baptist University · HK · Educationransomthegentlemen reclama a Eva Care · GB · Healthcareransomthegentlemen reclama a Premier Pigs · GB · Agriculture and Food Productionransomthegentlemen reclama a Zion Contracting · US · Otherransomplay reclama a MIE Solutions · GB · Professional Servicesransomunsafe reclama a DECK APP TECHNOLOGIES PTE. LTD · IN · Technologyransomthegentlemen reclama a CONTAC Ingenieros · CL · Professional Servicesransomthegentlemen reclama a RAK Construction · IN · Manufacturingransomthegentlemen reclama a Lancesoft India · IN · Technologyransomthegentlemen reclama a AIMS Group · GB · Otherransomthegentlemen reclama a AnMed · US · Healthcareransomthegentlemen reclama a NTU Alumni Club · SG · Educationransomthegentlemen reclama a Canopy Support Services · CA · Professional Servicesransomthegentlemen reclama a Mikel Coffee · MX · Retail & E-Commerceransomthegentlemen reclama a Hong Kong Baptist University · HK · Educationransomthegentlemen reclama a Eva Care · GB · Healthcareransomthegentlemen reclama a Premier Pigs · GB · Agriculture and Food Productionransomthegentlemen reclama a Zion Contracting · US · Otherransomplay reclama a MIE Solutions · GB · Professional Services
← All CVEs
CVE WatchJul 22, 2026

CVE-2019-25722

Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code an

CVSS

7.6

High

EPSS

0.2%

p9

KEV

Exploit Today

3

0-100

Published: Jun 2, 2026 · Last modified: Jul 22, 2026 · CWE-798

EPSS · 30d
0.2%EPSS · 30 days0.2%
2026-07-122026-08-08
Technical description

Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denial-of-service vulnerability that allows local and remote attackers to compromise device integrity across all software versions. A local attacker with direct device access can use the hard-coded credentials to access service and clinical accounts and alter device configuration, while a remote attacker can send malformed network packets to cause repeated device reboots, ultimately resulting in loss of network connectivity and disruption of patient monitoring.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-490077.5 HIG
27.2%
8By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.3d
CVE-2025-638239.8 CRI
36.0%
11My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.4d
CVE-2026-712389.1 CRI
23.7%
7DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens, achieving full account takeover. The repository also ships with DEBUG=True as the default, causing error pages to leak database credentials, email credentials, OAuth data, and internal file paths.5d
CVE-2026-480319.1 CRI
27.2%
8go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public repository forge tokens for arbitrary users, including admin roles, and completely bypass authentication on all protected endpoints. This value is set in two places: the dev.env template (line 10) and a programmatic fallback in cmd/serve.go (line 35), so the application uses it even when no .env file is present. The original mitigation in auth/jwt/tokenauth.go (lines 22 to 25) only caught the exact string "random", letting other weak secrets through, and replaced it with an in-memory key that was not persisted, invalidating all tokens on every restart and effectively causing a denial-of-service. This issue has been fixed in version 2026-05-18.7d
CVE-2025-156287.5 HIG
12.8%
4Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.3d
CVE-2026-653138.1 HIG
7.3%
2A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.10d