CWE-912
80 CVEs • Abstraction: Class
Hidden Functionality
The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.
CVEs (80)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of paramete...Show more |
1Solar Log 9Solar Log 1000 Firmware Solar Log 1000 Pm+ FirmwareSolar Log 1200 Firmware+6 moreJun 17, 2026 Jan 26, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects Solar-Log devices that use firmware version v4.2.7 up to v5.1.1 (included)...Show more |
Hidden functionality vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker to access the product via undocumented Telnet or SSH services. |
Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital c...Show more |
1Vsphere Selfuse Project 1Vsphere Selfuse Jun 17, 2026 Dec 14, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and di...Show more |
On ORing net IAP-420(+) with FW version 2.0m a telnet server is enabled by default and cannot permanently be disabled. You can connect to the device via LAN or WiFi with hardcoded credentials and get an administrative sh...Show more |
The tested version of Dominion Voting Systems ImageCast X has a Terminal Emulator application which could be leveraged by an attacker to gain elevated privileges on a device and/or install malicious code. |
1Jung Group 1Smart Visu Server Firmware Nov 21, 2024 Jun 22, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832 and classified as critical. Affected by this vulnerability is an unknown functionality of the component KNX Group Address. The manipulation...Show more |
1Jung Group 1Smart Visu Server Firmware Nov 21, 2024 Jun 22, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability, which was classified as critical, was found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. Affected is an unknown function of the component SSH Server. The manipulation leads to backdoor. An attack h...Show more |
1Jung Group 1Smart Visu Server Firmware Nov 21, 2024 Jun 22, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability, which was classified as problematic, has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. This issue affects some unknown processing. The manipulation leads to backdoor. The attack needs to...Show more |
1Ua Parser Js Project 1Ua Parser Js Jun 17, 2026 May 24, 2022 N/A· v4 8.8 HIGH· v3 7.6 HIGH· v2 A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is abl...Show more |
1Accesspressthemes 93Accessbuddy Accesspress LiteAccesspress Mag+90 moreJun 17, 2026 Feb 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those ho...Show more |
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface. |
A unauthenticated backdoor exists in the configuration server functionality of Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially crafted JSON object can lead to code execution. An attacker can send a malicious...Show more |
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. |
1Cisco 1Firepower Threat Defense Jun 17, 2026 Oct 21, 2020 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands. The vulnerability is due to the presence of undocumented configuration c...Show more |
3Korenix Pepperl FuchsWestermo29Es7506 Firmware Es7510 Xt FirmwareEs7510 Firmware+26 moreJun 17, 2026 Oct 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and...Show more |
1Redlion 2N Tron 702 W Firmware N Tron 702m12 W FirmwareJun 17, 2026 Sep 1, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as root on the device on the N-Tron 702-W / 702M12-W (all versions). |
1Freemedsoftware 1Openclinic Ga Jun 17, 2026 Jul 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this account, which may allow an attacker to login and execute arbitrary commands. |
1Xiongmaitech 1Xmeye P2p Cloud Server Nov 21, 2024 Oct 10, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video streams. |