Fallos del tipo CWE-912

88 resultados

Funcionalidade oculta ou não documentada

Funcionalidades presentes no código mas não reveladas ao usuário, documentação ou auditores — muitas vezes deixadas intencionalmente para bypass ou acesso privilegiado. O perigo é que atacantes descobrem e exploram essas portas de entrada não monitoradas, enquanto a organização não tem visibilidade ou controle sobre elas.

Ejemplo

Um aplicativo web contém um endpoint administrativo `/admin_debug` que não aparece na documentação ou interface; um atacante descobre por varredura de diretório e ganha acesso irrestrito aos dados. Ou um firmware que aceita uma sequência de comandos ocultos para ativar modo root.

Cómo mitigar

Remova todo código não utilizado ou não documentado antes de deploy em produção. Se recursos experimentais são necessários, documentá-los explicitamente e protegê-los com autenticação robusta. Audite periodicamente o código-fonte e binários para detectar funcionalidades não registradas.

CVE-2024-20439CRITICALA vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by usEPSS 92.1%KEVCVE-2025-34117CRITICALNetcore / Netis Routers RCE via UDP Port 53413 BackdoorEPSS 27.4%CVE-2021-24867Backdoored Plugins & Themes from AccessPress ThemesEPSS 18.0%CVE-2024-6045HIGHD-Link router - Hidden BackdoorEPSS 6.3%CVE-2020-16204The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as EPSS 5.5%CVE-2010-20103CRITICALProFTPD 1.3.3c Backdoor Command ExecutionEPSS 5.1%CVE-2020-12504CRITICALPepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx productsEPSS 3.0%CVE-2020-14487CRITICALOpenClinic GAEPSS 2.2%CVE-2022-38452HIGHA command execution vulnerability exists in the hidden telnet service functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-craftEPSS 2.1%CVE-2022-36429HIGHA command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS750 4.6.8.5. A speciaEPSS 2.0%CVE-2011-10018CRITICALmyBB 1.6.4 Backdoor Arbitrary Command ExecutionEPSS 2.0%CVE-2020-28593HIGHA unauthenticated backdoor exists in the configuration server functionality of Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially EPSS 1.9%CVE-2026-61515CRITICALPuwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShellEPSS 1.6%CVE-2025-32370HIGHKentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, becausEPSS 1.5%CVE-2021-4229MEDIUMua-parser-js Crypto Mining backdoorEPSS 1.4%CVE-2018-17919All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "defaEPSS 1.4%CVE-2023-24108CRITICALMvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.EPSS 1.4%CVE-2025-27840MEDIUMEspressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).EPSS 1.3%CVE-2024-39754CRITICALA static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network pacEPSS 1.3%CVE-2023-40158HIGHHidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the deviEPSS 1.3%