CWE-912
87 CVEs • Abstraction: Class
Hidden Functionality
The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.
CVEs (87)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A unauthenticated backdoor exists in the configuration server functionality of Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially crafted JSON object can lead to code execution. An attacker can send a malicious...Show more |
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. |
1Cisco 2Firepower Threat Defense Secure Firewall Threat DefenseAug 11, 2026 Oct 21, 2020 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands. The vulnerability is due to the presence of undocumented configuration c...Show more |
3Korenix Pepperl FuchsWestermo29Es7506 Firmware Es7510 Xt FirmwareEs7510 Firmware+26 moreJun 17, 2026 Oct 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and...Show more |
1Redlion 2N Tron 702 W Firmware N Tron 702m12 W FirmwareJun 17, 2026 Sep 1, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as root on the device on the N-Tron 702-W / 702M12-W (all versions). |
1Freemedsoftware 1Openclinic Ga Jun 17, 2026 Jul 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this account, which may allow an attacker to login and execute arbitrary commands. |
1Xiongmaitech 1Xmeye P2p Cloud Server Nov 21, 2024 Oct 10, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video streams. |