Falhas do tipo CWE-912

88 resultados

Funcionalidade oculta

A aplicação contém código ou lógica que não é documentada, não é evidente na interface e não é esperada pelos usuários ou administradores. Essa funcionalidade oculta pode ser explorada por atacantes para contornar controles de segurança, acessar dados sensíveis ou executar ações não autorizadas.

Exemplo

Um firmware de roteador contém um endpoint HTTP oculto que aceita comandos de shell sem autenticação. Desenvolvedores esqueceram de remover código de debug, e atacantes descobrem a funcionalidade ao fazer engenharia reversa, ganhando acesso administrativo total ao dispositivo.

Como mitigar

Remova todo código debug, backdoors e funcionalidades não documentadas antes de liberar para produção. Implemente revisão de código rigorosa, testes de segurança estáticos/dinâmicos e auditoria de binários para detectar lógica inesperada. Documente e mantenha registrado tudo o que a aplicação deve fazer.

CVE-2017-20083MEDIUMJUNG Smart Visu Server SSH Server backdoorEPSS 0.4%CVE-2026-33280HIGHHidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging fuEPSS 0.4%CVE-2017-20082MEDIUMJUNG Smart Visu Server backdoorEPSS 0.4%CVE-2026-17032CRITICALSupsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update ServerEPSS 0.4%CVE-2017-20084MEDIUMJUNG Smart Visu Server KNX Group Address backdoorEPSS 0.4%CVE-2025-55075MEDIUMHidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled by a remote authentiEPSS 0.3%CVE-2025-8938MEDIUMTOTOLINK N350R Telnet Service formSysTel backdoorEPSS 0.3%CVE-2025-46267MEDIUMHidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited, the product's hidden debug function may be enabled by a remoEPSS 0.3%CVE-2026-30704CRITICALThe WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCBEPSS 0.3%CVE-2024-37994MEDIUMA vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6EPSS 0.3%CVE-2025-11544CRITICALImproper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthEPSS 0.3%CVE-2025-6839MEDIUMConjure Position Department Service Quality Evaluation System head.php eval backdoorEPSS 0.3%CVE-2026-34769HIGHElectron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferenceEPSS 0.3%CVE-2026-15413CRITICALLink Factory - BackdoorEPSS 0.3%CVE-2023-22316MEDIUMHidden functionality vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker EPSS 0.3%CVE-2026-80217HIGHHidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode oEPSS 0.3%CVE-2022-1741MEDIUM2.2.3 HIDDEN FUNCTIONALITY CWE-912EPSS 0.3%CVE-2020-3352MEDIUMCisco Firepower Threat Defense Software Hidden Commands VulnerabilityEPSS 0.3%CVE-2026-1952CRITICALDenial of service via the undocumented subfunction in AS320TEPSS 0.3%CVE-2025-26412MEDIUMUndocumented Root Shell Access in SIMCom SIM7600G ModemEPSS 0.3%