Falhas do tipo CWE-1242

14 resultados

Inclusão de funcionalidades não documentadas ou flags de debug

Código contém recursos ocultos, modos de teste ou chaves de controle ('chicken bits') que não estão documentados e não são removidos antes da produção. Esses mecanismos podem ser descobertos e explorados por atacantes para contornar controles de segurança, escalar privilégios ou acessar funcionalidades administrativas sem autorização.

Exemplo

Um firmware de roteador incluir um comando SSH secreto de debug que permite shell remoto sem autenticação, ou um app ter um parâmetro não documentado que, quando ativado via requisição HTTP, desabilita validação de entrada. Se descobertos, viram porta de entrada para compromissão.

Como mitigar

Remova ou desative completamente todo código de debug, testes e flags experimentais antes do release. Se precisar manter funcionalidades internas, proteja-as com autenticação forte e revise rigorosamente o inventário de features antes de cada deploy — toda funcionalidade não documentada é potencialmente um risco.

CVE-2017-20204CRITICALDBLTek GoIP Telnet Admin Interface Undocumented BackdoorEPSS 0.8%CVE-2021-4469HIGHDenver SHO-110 IP Camera Unauthenticated Snapshot AccessEPSS 0.6%CVE-2024-52564HIGHInclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 anEPSS 0.6%CVE-2023-3634HIGHFesto: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible FunctionsEPSS 0.5%CVE-2024-2103MEDIUMInclusion of Undocumented FeaturesEPSS 0.5%CVE-2024-54457HIGHInclusion of undocumented features or chicken bits issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versionEPSS 0.4%CVE-2025-22450HIGHInclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may disable the LAN-side fEPSS 0.4%CVE-2025-52548MEDIUMEnabling SSH and Shellinabox on the vulnerable machineEPSS 0.3%CVE-2025-41754MEDIUMArbitrary Read with ubr-editfileEPSS 0.3%CVE-2025-41756HIGHArbitrary Write with ubr-editfileEPSS 0.3%CVE-2025-12176CRITICALUndocumented Administrative AccountsEPSS 0.3%CVE-2025-55050CRITICALCWE-1242: Inclusion of Undocumented FeaturesEPSS 0.3%CVE-2024-7011MEDIUMSharp NEC Projectors (NP-CB4500UL, NP-CB4500WL, NP-CB4700UL, NP-P525UL, NP-P525UL+, NP-P525ULG, NP-P525ULJL, NP-P525WL, NP-P525WL+, NP-P525WEPSS 0.3%CVE-2026-24714HIGHSome end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telnet service on the boxEPSS 0.2%