CWE-912— Hidden Functionality
The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.— MITRE CWE catalog
89 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-912page 2 of 2
- CVE-2017-20084HIGHCVSS 5.3EG 7.82022-06-22
A vulnerability has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832 and classified as critical. Affected by this vulnerability is an unknown functionality of the component KNX Group Address. The manipulation leads to backdoor.…
- CVE-2017-20083HIGHCVSS 5.3EG 7.82022-06-22
A vulnerability, which was classified as critical, was found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. Affected is an unknown function of the component SSH Server. The manipulation leads to backdoor. An attack has to be approached…
- CVE-2025-1204HIGHCVSS 7.7EG 7.72025-02-25
The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to do so. The function triggers if the 'C' button is pressed at a specific…
- CVE-2025-0675HIGHCVSS 7.5EG 7.52025-02-07
Multiple Elber products suffer from an unauthenticated device configuration and client-side hidden functionality disclosure.
- CVE-2025-0626HIGHCVSS 7.5EG 7.52025-01-30
The "monitor" binary in the firmware of the affected product attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to do so. The function also enables the network interface of the device if it i…
- CVE-2024-5633HIGHCVSS 7.5EG 7.52024-07-09
Longse model LBH30FE200W cameras, as well as products based on this device, provide an unrestricted access for an attacker located in the same local network to an undocumented binary service CoolView on one of the ports. An attacker wit…
- CVE-2024-22044HIGHCVSS 7.5EG 7.52024-03-12
A vulnerability has been identified in SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (All versions). Affected devices expose an unused, unstable http service at port 80/tcp on the Modbus-TCP Ethernet. This could allow an attac…
- CVE-2026-7413HIGHCVSS 7.2EG 7.22026-05-07
A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings,…
- CVE-2025-48418HIGHCVSS 7.2EG 7.22026-03-10
A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cl…
- CVE-2025-58778HIGHCVSS 7.2EG 7.22025-10-16
Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the manual, and enabled in the initial configuration. Anyone with the knowledge of the related credentials can log in to t…
- CVE-2025-11673HIGHCVSS 7.2EG 7.22025-10-13
SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploit a hidden functionality to execute arbitrary code on the server.
- CVE-2025-32370HIGHCVSS 7.2EG 7.22025-04-06
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files w…
- CVE-2024-13062HIGHCVSS 7.2EG 7.22025-01-02
An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for …
- CVE-2022-36429HIGHCVSS 7.2EG 7.22023-03-21
A command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS750 4.6.8.5. A specially-crafted JSON object can lead to arbitrary command execution. An attacker can send a sequence of…
- CVE-2025-26412MEDIUMCVSS 6.8EG 6.82025-06-11
The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker needs either physical access or remote shell access to a device that interact…
- CVE-2025-27840MEDIUMCVSS 6.8EG 6.82025-03-08
Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
- CVE-2023-42134MEDIUMCVSS 6.8EG 6.82024-01-15
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subsequently local code execution via hidden command. The attacker must have physical USB access t…
- CVE-2022-1741MEDIUMCVSS 6.8EG 6.82022-06-24
The tested version of Dominion Voting Systems ImageCast X has a Terminal Emulator application which could be leveraged by an attacker to gain elevated privileges on a device and/or install malicious code.
- CVE-2026-1741MEDIUMCVSS 6.6EG 6.62026-02-02
A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This manipulation of the argument cmd causes backdoor. It is poss…
- CVE-2025-2894MEDIUMCVSS 6.6EG 6.62025-03-28
The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remot…
- CVE-2023-4467MEDIUMCVSS 6.6EG 6.62023-12-29
A vulnerability was found in Poly Trio 8800 7.2.6.0019 and classified as critical. Affected by this issue is some unknown functionality of the component Test Automation Mode. The manipulation leads to backdoor. It is possible to launch the…
- CVE-2024-37990MEDIUMCVSS 6.5EG 6.52024-09-10
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versi…
- CVE-2023-22316MEDIUMCVSS 6.5EG 6.52023-01-17
Hidden functionality vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker to access the product via undocumented Telnet or SSH services.
- CVE-2018-17919MEDIUMCVSS 6.5EG 6.52018-10-10
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video streams.
- CVE-2025-9382MEDIUMCVSS 6.4EG 6.42025-08-24
A weakness has been identified in FNKvision Y215 CCTV Camera 10.194.120.40. This vulnerability affects unknown code of the file s1_rf_test_config of the component Telnet Sevice. Executing manipulation can lead to backdoor. The physical dev…
- CVE-2025-8938MEDIUMCVSS 6.3EG 6.32025-08-14
A vulnerability was found in TOTOLINK N350R 1.2.3-B20130826. This issue affects the function formSysTel of the file /boafrm/formSysTel of the component Telnet Service. The manipulation of the argument TelEnabled leads to backdoor. The atta…
- CVE-2025-6839MEDIUMCVSS 6.3EG 6.32025-06-29
A vulnerability, which was classified as critical, has been found in Conjure Position Department Service Quality Evaluation System up to 1.0.11. Affected by this issue is the function eval of the file public/assets/less/bootstrap-less/mixi…
- CVE-2026-4621MEDIUMCVSS 5.6EG 5.62026-03-27
Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.
- CVE-2017-20082MEDIUMCVSS 5.5EG 5.52022-06-22
A vulnerability, which was classified as problematic, has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. This issue affects some unknown processing. The manipulation leads to backdoor. The attack needs to be approached local…
- CVE-2020-3352MEDIUMCVSS 5.5EG 5.52020-10-21
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands. The vulnerability is due to the presence of undocumented configuration commands. An attacke…
- CVE-2025-55704MEDIUMCVSS 5.3EG 5.32026-01-29
Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to obtain the logs of the affected product and obtain sensitive information within the logs.
- CVE-2021-36403MEDIUMCVSS 5.3EG 5.32023-03-06
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
- CVE-2021-4229MEDIUMCVSS 5.0EG 5.02022-05-24
A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this i…
- CVE-2025-55075MEDIUMCVSS 4.9EG 4.92025-09-17
Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled by a remote authenticated attacker.
- CVE-2025-46267MEDIUMCVSS 4.9EG 4.92025-07-22
Hidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited, the product's hidden debug function may be enabled by a remote attacker who can log in to WebGUI.
- CVE-2024-37994MEDIUMCVSS 4.3EG 4.32024-09-10
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versi…
- CVE-2024-33583LOWCVSS 3.3EG 3.32024-05-14
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All ver…
- CVE-2023-6614LOWCVSS 2.7EG 2.72023-12-08
A vulnerability classified as problematic was found in Typecho 1.2.1. Affected by this vulnerability is an unknown functionality of the file /admin/manage-pages.php of the component Page Handler. The manipulation leads to backdoor. The att…
- CVE-2025-62773LOWCVSS 2.4EG 2.42025-10-22
Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.
Map vulnerabilities like CWE-912 to your infrastructure
EchelonGraph correlates every CVE — across CWE-912 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →