CWE-912— Hidden Functionality
The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.— MITRE CWE catalog
89 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-912page 1 of 2
- CVE-2024-20439CRITICALCVSS 9.8EG 9.8⚠ KEV2024-09-04
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user…
- CVE-2021-25371CRITICALCVSS 6.1EG 9.0⚠ KEV2021-03-26
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
- CVE-2025-47729CRITICALCVSS 1.9EG 9.0⚠ KEV2025-05-08
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile …
- CVE-2026-15413CRITICALCVSS 10.0EG 10.02026-08-13
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a …
- CVE-2026-14812CRITICALCVSS 10.0EG 10.02026-08-06
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end sc…
- CVE-2026-11976CRITICALCVSS 10.0EG 10.02026-08-06
The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-s…
- CVE-2026-3587CRITICALCVSS 10.0EG 10.02026-03-23
An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.
- CVE-2024-39754CRITICALCVSS 10.0EG 10.02025-01-14
A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network packets can lead to root access. An attacker can send packets to trigger this vulnerability.
- CVE-2026-82829CRITICALCVSS 9.8EG 9.82026-10-01
Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials. This issue affects Hitachi…
- CVE-2026-17032CRITICALCVSS 9.8EG 9.82026-08-06
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data a…
- CVE-2026-61515CRITICALCVSS 9.8EG 9.82026-08-04
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell …
- CVE-2026-18191CRITICALCVSS 9.8EG 9.82026-07-29
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device.
- CVE-2026-4769CRITICALCVSS 9.8EG 9.82026-07-13
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief per…
- CVE-2026-41446CRITICALCVSS 9.8EG 9.82026-04-28
Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on th…
- CVE-2026-1952CRITICALCVSS 9.8EG 9.82026-04-24
Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.
- CVE-2026-33280CRITICALCVSS 9.8EG 9.82026-03-27
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.
- CVE-2010-20103CRITICALCVSS 9.8EG 9.82025-08-20
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arb…
- CVE-2011-10018CRITICALCVSS 9.8EG 9.82025-08-13
myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting payloads into a specially crafted collapsed cookie. This vulnera…
- CVE-2024-45697CRITICALCVSS 9.8EG 9.82024-09-16
Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS commands using hard-coded credentials.
- CVE-2024-5514CRITICALCVSS 9.8EG 9.82024-05-30
MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access contro…
- CVE-2024-28011CRITICALCVSS 9.8EG 9.82024-03-28
Hidden Functionality vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG…
- CVE-2023-24108CRITICALCVSS 9.8EG 9.82023-02-22
MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrar…
- CVE-2022-47767CRITICALCVSS 9.8EG 9.82023-01-26
A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects Solar-Log devices that use firmware version v4.2.7 up to v5.1.1 (included). This does not exi…
- CVE-2022-46997CRITICALCVSS 9.8EG 9.82022-12-14
Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as we…
- CVE-2022-46996CRITICALCVSS 9.8EG 9.82022-12-14
vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys…
- CVE-2022-3203CRITICALCVSS 9.8EG 9.82022-10-21
On ORing net IAP-420(+) with FW version 2.0m a telnet server is enabled by default and cannot permanently be disabled. You can connect to the device via LAN or WiFi with hardcoded credentials and get an administrative shell. These credenti…
- CVE-2021-24867CRITICALCVSS 9.8EG 9.82022-02-21
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.o…
- CVE-2021-43987CRITICALCVSS 9.8EG 9.82021-12-23
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.
- CVE-2020-12504CRITICALCVSS 9.8EG 9.82020-10-15
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G…
- CVE-2020-16204CRITICALCVSS 9.8EG 9.82020-09-01
The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as root on the device on the N-Tron 702-W / 702M12-W (all versions).
- CVE-2025-11544CRITICALCVSS 9.5EG 9.52025-12-22
Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized firmware.
- CVE-2020-14487CRITICALCVSS 9.4EG 9.42020-07-29
OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this account, which may allow an attacker to login and execute arbitrary commands.
- CVE-2025-34117CRITICALCVSS 9.3EG 9.32025-07-16
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the presence of an undocumented backdoor listener on UDP port 53413. Exact version boundaries rema…
- CVE-2026-30704CRITICALCVSS 9.1EG 9.12026-03-18
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB
- CVE-2024-3016CRITICALCVSS 9.1EG 9.12024-05-14
NEC Platforms DT900 and DT900S Series 5.0.0.0 – v5.3.4.4, v5.4.0.0 – v5.6.0.20 allows an attacker to access a non-documented the system settings to change settings via local network with unauthenticated user.
- CVE-2022-3843CRITICALCVSS 9.1EG 9.12023-02-16
In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.
- CVE-2024-10773CRITICALCVSS 9.0EG 9.02024-12-06
The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain full access to the device.
- CVE-2026-80217HIGHCVSS 8.8EG 8.82026-09-15
Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.
- CVE-2026-34769HIGHCVSS 8.8EG 8.82026-04-04
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switch…
- CVE-2026-31847HIGHCVSS 8.8EG 8.82026-03-23
Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters such as telnetMana…
- CVE-2025-30064HIGHCVSS 8.8EG 8.82025-08-27
An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an attacker can use the "ex:action" param…
- CVE-2024-47001HIGHCVSS 8.8EG 8.82024-09-18
Hidden functionality issue in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
- CVE-2024-45696HIGHCVSS 8.8EG 8.82024-09-16
Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded credentials. The telnet service enabled…
- CVE-2024-6045HIGHCVSS 8.8EG 8.82024-06-17
Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by usin…
- CVE-2023-40158HIGHCVSS 8.8EG 8.82023-08-23
Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provi…
- CVE-2022-38452HIGHCVSS 7.2EG 8.82023-03-21
A command execution vulnerability exists in the hidden telnet service functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request …
- CVE-2023-25183HIGHCVSS 8.3EG 8.32023-05-22
In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appears that could allow users to execute arbitrary commands on the hub device.
- CVE-2026-18844HIGHCVSS 8.1EG 8.12026-08-11
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion m…
- CVE-2025-48416HIGHCVSS 8.1EG 8.12025-05-21
An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image for the "root" user. However, in the default SSH configuration the "PermitRootLogin" is disabled, preventing the root use…
- CVE-2020-28593HIGHCVSS 8.1EG 8.12021-04-15
A unauthenticated backdoor exists in the configuration server functionality of Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially crafted JSON object can lead to code execution. An attacker can send a malicious packet to trigger …
Map vulnerabilities like CWE-912 to your infrastructure
EchelonGraph correlates every CVE — across CWE-912 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →