Falhas do tipo CWE-912

88 resultados

Funcionalidade oculta

A aplicação contém código ou lógica que não é documentada, não é evidente na interface e não é esperada pelos usuários ou administradores. Essa funcionalidade oculta pode ser explorada por atacantes para contornar controles de segurança, acessar dados sensíveis ou executar ações não autorizadas.

Exemplo

Um firmware de roteador contém um endpoint HTTP oculto que aceita comandos de shell sem autenticação. Desenvolvedores esqueceram de remover código de debug, e atacantes descobrem a funcionalidade ao fazer engenharia reversa, ganhando acesso administrativo total ao dispositivo.

Como mitigar

Remova todo código debug, backdoors e funcionalidades não documentadas antes de liberar para produção. Implemente revisão de código rigorosa, testes de segurança estáticos/dinâmicos e auditoria de binários para detectar lógica inesperada. Documente e mantenha registrado tudo o que a aplicação deve fazer.

CVE-2022-46996CRITICALvSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package.EPSS 1.3%CVE-2022-47767CRITICALA backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This afEPSS 1.2%CVE-2021-43987CRITICALmySCADA myPROEPSS 1.2%CVE-2025-0626HIGHHidden Functionality vulnerability in Contec Health CMS8000 Patient MonitorEPSS 1.2%CVE-2022-46997CRITICALPasshunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package. This vEPSS 1.1%CVE-2024-45697CRITICALD-Link WiFi router - Hidden FunctionalityEPSS 1.0%CVE-2024-13062HIGHAn unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. ReferEPSS 1.0%CVE-2022-3203CRITICALORing net IAP-420(+) Hidden FunctionalityEPSS 0.9%CVE-2022-3843CRITICALWAGO: Exposure of configuration interface in unmanaged switchesEPSS 0.9%CVE-2025-2894MEDIUMUnitree Go1 Robot Dog Backdoor Control ChannelEPSS 0.8%CVE-2021-25371MEDIUMA vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.EPSS 0.8%KEVCVE-2026-4769CRITICALUnauthenticated Access to Internal Diagnostic InterfaceEPSS 0.8%CVE-2024-3016CRITICALNEC Platforms DT900 and DT900S Series 5.0.0.0 – v5.3.4.4, v5.4.0.0 – v5.6.0.20 allows an attacker to access a non-documented the system settEPSS 0.7%CVE-2026-3587CRITICALHidden CLI Function Allows Root AccessEPSS 0.7%CVE-2024-47001HIGHHidden functionality issue in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attaEPSS 0.7%CVE-2024-5514CRITICALMinMax CMS - Hidden FunctionalityEPSS 0.7%CVE-2023-6614LOWTypecho Page manage-pages.php backdoorEPSS 0.6%CVE-2023-25183HIGH In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appEPSS 0.6%CVE-2024-28011CRITICALHidden Functionality vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG12EPSS 0.6%CVE-2024-5633HIGHLongse model LBH30FE200W cameras, as well as products based on this device, provide an unrestricted access for an attacker located in the saEPSS 0.6%