CWE-912— Hidden Functionality
The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.— MITRE CWE catalog
87 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-912page 2 of 2
- CVE-2025-11673HIGHCVSS 7.2EG 7.22025-10-13
SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploit a hidden functionality to execute arbitrary code on the server.
- CVE-2025-1204HIGHCVSS 7.7EG 7.72025-02-25
The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to do so. The function triggers if the 'C' button is pressed at a specific…
- CVE-2025-26412MEDIUMCVSS 6.8EG 6.82025-06-11
The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker needs either physical access or remote shell access to a device that interact…
- CVE-2025-27840MEDIUMCVSS 6.8EG 6.82025-03-08
Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
- CVE-2025-2894MEDIUMCVSS 6.6EG 6.62025-03-28
The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remot…
- CVE-2025-30064HIGHCVSS 8.8EG 8.82025-08-27
An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an attacker can use the "ex:action" param…
- CVE-2025-32370HIGHCVSS 7.2EG 7.22025-04-06
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files w…
- CVE-2025-34117CRITICALCVSS 9.3EG 9.32025-07-16
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the presence of an undocumented backdoor listener on UDP port 53413. Exact version boundaries rema…
- CVE-2025-46267MEDIUMCVSS 4.9EG 4.92025-07-22
Hidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited, the product's hidden debug function may be enabled by a remote attacker who can log in to WebGUI.
- CVE-2025-47729CRITICALCVSS 1.9EG 9.0⚠ KEV2025-05-08
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile …
- CVE-2025-48416HIGHCVSS 8.1EG 8.12025-05-21
An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image for the "root" user. However, in the default SSH configuration the "PermitRootLogin" is disabled, preventing the root use…
- CVE-2025-48418HIGHCVSS 7.2EG 7.22026-03-10
A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cl…
- CVE-2025-55075MEDIUMCVSS 4.9EG 4.92025-09-17
Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled by a remote authenticated attacker.
- CVE-2025-55704MEDIUMCVSS 5.3EG 5.32026-01-29
Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to obtain the logs of the affected product and obtain sensitive information within the logs.
- CVE-2025-58778HIGHCVSS 7.2EG 7.22025-10-16
Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the manual, and enabled in the initial configuration. Anyone with the knowledge of the related credentials can log in to t…
- CVE-2025-62773LOWCVSS 2.4EG 2.42025-10-22
Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.
- CVE-2025-6839MEDIUMCVSS 6.3EG 6.32025-06-29
A vulnerability, which was classified as critical, has been found in Conjure Position Department Service Quality Evaluation System up to 1.0.11. Affected by this issue is the function eval of the file public/assets/less/bootstrap-less/mixi…
- CVE-2025-8938MEDIUMCVSS 6.3EG 6.32025-08-14
A vulnerability was found in TOTOLINK N350R 1.2.3-B20130826. This issue affects the function formSysTel of the file /boafrm/formSysTel of the component Telnet Service. The manipulation of the argument TelEnabled leads to backdoor. The atta…
- CVE-2025-9382MEDIUMCVSS 6.4EG 6.42025-08-24
A weakness has been identified in FNKvision Y215 CCTV Camera 10.194.120.40. This vulnerability affects unknown code of the file s1_rf_test_config of the component Telnet Sevice. Executing manipulation can lead to backdoor. The physical dev…
- CVE-2026-11976CRITICALCVSS 10.0EG 10.02026-08-06
The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-s…
- CVE-2026-14812CRITICALCVSS 10.0EG 10.02026-08-06
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end sc…
- CVE-2026-15413CRITICALCVSS 10.0EG 10.02026-08-13
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a …
- CVE-2026-17032CRITICALCVSS 9.8EG 9.82026-08-06
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data a…
- CVE-2026-1741MEDIUMCVSS 6.6EG 6.62026-02-02
A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This manipulation of the argument cmd causes backdoor. It is poss…
- CVE-2026-18191CRITICALCVSS 9.8EG 9.82026-07-29
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device.
- CVE-2026-18844HIGHCVSS 8.1EG 8.12026-08-11
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion m…
- CVE-2026-1952CRITICALCVSS 9.8EG 9.82026-04-24
Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.
- CVE-2026-30704CRITICALCVSS 9.1EG 9.12026-03-18
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB
- CVE-2026-31847HIGHCVSS 8.8EG 8.82026-03-23
Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters such as telnetMana…
- CVE-2026-33280CRITICALCVSS 9.8EG 9.82026-03-27
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.
- CVE-2026-34769HIGHCVSS 8.8EG 8.82026-04-04
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switch…
- CVE-2026-3587CRITICALCVSS 10.0EG 10.02026-03-23
An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.
- CVE-2026-41446CRITICALCVSS 9.8EG 9.82026-04-28
Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on th…
- CVE-2026-4621MEDIUMCVSS 5.6EG 5.62026-03-27
Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.
- CVE-2026-4769CRITICALCVSS 9.8EG 9.82026-07-13
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief per…
- CVE-2026-61515CRITICALCVSS 9.8EG 9.82026-08-04
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell …
- CVE-2026-7413HIGHCVSS 7.2EG 7.22026-05-07
A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings,…
Map vulnerabilities like CWE-912 to your infrastructure
EchelonGraph correlates every CVE — across CWE-912 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →