Fallos del tipo CWE-912

88 resultados

Funcionalidade oculta ou não documentada

Funcionalidades presentes no código mas não reveladas ao usuário, documentação ou auditores — muitas vezes deixadas intencionalmente para bypass ou acesso privilegiado. O perigo é que atacantes descobrem e exploram essas portas de entrada não monitoradas, enquanto a organização não tem visibilidade ou controle sobre elas.

Ejemplo

Um aplicativo web contém um endpoint administrativo `/admin_debug` que não aparece na documentação ou interface; um atacante descobre por varredura de diretório e ganha acesso irrestrito aos dados. Ou um firmware que aceita uma sequência de comandos ocultos para ativar modo root.

Cómo mitigar

Remova todo código não utilizado ou não documentado antes de deploy em produção. Se recursos experimentais são necessários, documentá-los explicitamente e protegê-los com autenticação robusta. Audite periodicamente o código-fonte e binários para detectar funcionalidades não registradas.

CVE-2017-20083MEDIUMJUNG Smart Visu Server SSH Server backdoorEPSS 0.4%CVE-2026-33280HIGHHidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging fuEPSS 0.4%CVE-2017-20082MEDIUMJUNG Smart Visu Server backdoorEPSS 0.4%CVE-2026-17032CRITICALSupsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update ServerEPSS 0.4%CVE-2017-20084MEDIUMJUNG Smart Visu Server KNX Group Address backdoorEPSS 0.4%CVE-2025-55075MEDIUMHidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled by a remote authentiEPSS 0.3%CVE-2025-8938MEDIUMTOTOLINK N350R Telnet Service formSysTel backdoorEPSS 0.3%CVE-2025-46267MEDIUMHidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited, the product's hidden debug function may be enabled by a remoEPSS 0.3%CVE-2026-30704CRITICALThe WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCBEPSS 0.3%CVE-2024-37994MEDIUMA vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6EPSS 0.3%CVE-2025-11544CRITICALImproper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthEPSS 0.3%CVE-2025-6839MEDIUMConjure Position Department Service Quality Evaluation System head.php eval backdoorEPSS 0.3%CVE-2026-34769HIGHElectron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferenceEPSS 0.3%CVE-2026-15413CRITICALLink Factory - BackdoorEPSS 0.3%CVE-2023-22316MEDIUMHidden functionality vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker EPSS 0.3%CVE-2026-80217HIGHHidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode oEPSS 0.3%CVE-2022-1741MEDIUM2.2.3 HIDDEN FUNCTIONALITY CWE-912EPSS 0.3%CVE-2020-3352MEDIUMCisco Firepower Threat Defense Software Hidden Commands VulnerabilityEPSS 0.3%CVE-2026-1952CRITICALDenial of service via the undocumented subfunction in AS320TEPSS 0.3%CVE-2025-26412MEDIUMUndocumented Root Shell Access in SIMCom SIM7600G ModemEPSS 0.3%