Threadlinqs IntelligenceStart free

Weakness · VariantCWE-321

CWE-321: Use of Hard-coded Cryptographic Key

Likelihood of exploit: HighKEV-linkedVariant

As of 2026-10-05, CWE-321 (Use of Hard-coded Cryptographic Key) underlies 10 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 19 tracked threats. MITRE rates its likelihood of exploit as High.

CVEs
10Mapped to CWE-321
CISA KEV
2Exploited in the wild
Critical
5CVSS v3 critical CVEs
Threats
19Tracked campaigns citing it
Likelihood
HighMITRE likelihood of exploit

Last updated:

What is CWE-321?

The product uses a hard-coded, unchangeable cryptographic key.

CWE-321 is a variant-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Not Language-Specific; ICS/OT.

Source: MITRE CWE (CWE-321 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control — Bypass Protection Mechanism, Gain Privileges or Assume Identity, Read Application Data. If hard-coded cryptographic keys are used, it is almost certain that malicious users will gain access through the account in question. The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.

Source: MITRE CWE, common consequences.

How CWE-321 is exploited in the wild

Threadlinqs maps 10 CVEs to CWE-321, published between 2016-06-07 and 2026-10-01. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 5 critical, 1 high, 2 medium. The highest EPSS score in the set is 94.3% (CVE-2025-30406), the modelled probability of exploitation in the next 30 days. 19 tracked threats reference CWE-321 directly or through a CVE it covers; the most recent is “Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)” (2026-10-02). Affected products concentrate in Apache (1), Digital Knowledge (1), Flowise (1), among 11 vendors in total.

Vulnerabilities (CVEs)

All 10 CVEs mapped to CWE-321, CISA KEV first, then by CVSS score.

Affected vendors

  • Apache — 1 CVE
  • Digital Knowledge — 1 CVE
  • Flowise — 1 CVE
  • Gladinet — 1 CVE
  • Johnson Controls — 1 CVE
  • Redhat — 1 CVE
  • SolarWinds — 1 CVE
  • TP-Link Systems Inc. — 1 CVE
  • Unitree — 1 CVE
  • WWBN — 1 CVE
  • Wärtsilä — 1 CVE

Threat activity

19 tracked threats cite CWE-321:

Mitigations

  • Architecture and Design: Prevention schemes mirror that of hard-coded password storage.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.