Weaknesses of type CWE-912

88 results

Funcionalidade oculta não documentada

É quando o software contém recursos, rotinas ou comportamentos que não estão documentados, não são acessíveis pelo fluxo normal de uso, mas podem ser ativados por quem conhecer a técnica certa (entrada especial, parâmetro secreto, sequência de ações). Isso deixa a superfície de ataque invisível e incontrolável.

Example

Um firmware de roteador que responde a uma requisição HTTP com parâmetro 'admin_backdoor=1' para contornar autenticação, ou um app mobile que ativa modo de debug ao tocar na tela 10 vezes seguidas em um canto específico, exposição silenciosa de credenciais hardcoded.

How to mitigate

Remova todo código de teste, debug ou acesso administrativo antes de produção. Documente e teste cada entrada possível de usuário. Use análise estática para caçar constantes suspeitas, URLs de debug ou flags hardcoded. Revise commits que adicionam 'backdoors temporários'.

CVE-2017-20083MEDIUMJUNG Smart Visu Server SSH Server backdoorEPSS 0.4%CVE-2026-33280HIGHHidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging fuEPSS 0.4%CVE-2017-20082MEDIUMJUNG Smart Visu Server backdoorEPSS 0.4%CVE-2026-17032CRITICALSupsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update ServerEPSS 0.4%CVE-2017-20084MEDIUMJUNG Smart Visu Server KNX Group Address backdoorEPSS 0.4%CVE-2025-55075MEDIUMHidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled by a remote authentiEPSS 0.3%CVE-2025-8938MEDIUMTOTOLINK N350R Telnet Service formSysTel backdoorEPSS 0.3%CVE-2025-46267MEDIUMHidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited, the product's hidden debug function may be enabled by a remoEPSS 0.3%CVE-2026-30704CRITICALThe WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCBEPSS 0.3%CVE-2024-37994MEDIUMA vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6EPSS 0.3%CVE-2025-11544CRITICALImproper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthEPSS 0.3%CVE-2025-6839MEDIUMConjure Position Department Service Quality Evaluation System head.php eval backdoorEPSS 0.3%CVE-2026-34769HIGHElectron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferenceEPSS 0.3%CVE-2026-15413CRITICALLink Factory - BackdoorEPSS 0.3%CVE-2023-22316MEDIUMHidden functionality vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker EPSS 0.3%CVE-2026-80217HIGHHidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode oEPSS 0.3%CVE-2022-1741MEDIUM2.2.3 HIDDEN FUNCTIONALITY CWE-912EPSS 0.3%CVE-2020-3352MEDIUMCisco Firepower Threat Defense Software Hidden Commands VulnerabilityEPSS 0.3%CVE-2026-1952CRITICALDenial of service via the undocumented subfunction in AS320TEPSS 0.3%CVE-2025-26412MEDIUMUndocumented Root Shell Access in SIMCom SIM7600G ModemEPSS 0.3%