Weaknesses of type CWE-912

88 results

Funcionalidade oculta não documentada

É quando o software contém recursos, rotinas ou comportamentos que não estão documentados, não são acessíveis pelo fluxo normal de uso, mas podem ser ativados por quem conhecer a técnica certa (entrada especial, parâmetro secreto, sequência de ações). Isso deixa a superfície de ataque invisível e incontrolável.

Example

Um firmware de roteador que responde a uma requisição HTTP com parâmetro 'admin_backdoor=1' para contornar autenticação, ou um app mobile que ativa modo de debug ao tocar na tela 10 vezes seguidas em um canto específico, exposição silenciosa de credenciais hardcoded.

How to mitigate

Remova todo código de teste, debug ou acesso administrativo antes de produção. Documente e teste cada entrada possível de usuário. Use análise estática para caçar constantes suspeitas, URLs de debug ou flags hardcoded. Revise commits que adicionam 'backdoors temporários'.

CVE-2024-45696HIGHD-Link WiFi router - Hidden FunctionalityEPSS 0.6%CVE-2025-58778HIGHMultiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the manual, and enabledEPSS 0.6%CVE-2024-10773CRITICALSICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for pass-the-hash attacksEPSS 0.6%CVE-2025-11673HIGHPiExtract |SOOP-CLM - Hidden FunctionalityEPSS 0.6%CVE-2026-7413HIGHPersistent undocumented backdoor access in Yarbo robotEPSS 0.6%CVE-2026-14812CRITICALPremium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)EPSS 0.6%CVE-2023-42134MEDIUMPAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subsEPSS 0.6%CVE-2025-48416HIGHBackdoor Functionality via SSH in eCharge Hardy Barth cPH2 / cPP2 charging stationsEPSS 0.5%CVE-2021-36403MEDIUMIn Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which mayEPSS 0.5%CVE-2024-22044HIGHA vulnerability has been identified in SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (All versions). Affected devices expose anEPSS 0.5%CVE-2025-48418MEDIUMA hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 tEPSS 0.5%CVE-2025-0675HIGHElber Communications Equipment Hidden FunctionalityEPSS 0.5%CVE-2026-1741HIGHEFM ipTIME A8004T Debug d.cgi httpcon_check_session_url backdoorEPSS 0.5%CVE-2026-11976CRITICALMonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromiseEPSS 0.5%CVE-2025-1204HIGHThe "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address, bypassing existingEPSS 0.5%CVE-2026-41446CRITICALWattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic EndpointsEPSS 0.4%CVE-2025-47729LOWThe TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which iEPSS 0.4%KEVCVE-2026-31847HIGHHidden Functionality Enables Remote Telnet Activation via /goform/setSysTools in Nexxt Nebula 300+EPSS 0.4%CVE-2024-37990HIGHA vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6EPSS 0.4%CVE-2026-18191CRITICALVacron|IP Camera - Hidden FunctionalityEPSS 0.4%