EyesOfNetwork Use of Hard-Coded Credentials Vulnerability

Added to KEV
2021-11-03
Federal due date
2022-05-03
Vendor
EyesOfNetwork
Product
EyesOfNetwork
EPSS
99.5th percentile (score 0.889, as of 2026-06-08)
NVD CVSS v3.1
Ransomware use
Unknown
Upstream
https://nvd.nist.gov/vuln/detail/CVE-2020-8657

CISA short description

EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.

Required action

Apply updates per vendor instructions.

EPSS percentile is the FIRST.org exploit-probability ranking as of the date noted above; it moves daily. CVSS reflects NVD's analysis at time of publication.