CWE-1242: Inclusion of Undocumented Features or Chicken Bits
The device includes chicken bits or undocumented features that can create entry points for unauthorized actors.
14 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-12176 — Undocumented Administrative Accounts
- CVE-2025-55050 — CWE-1242: Inclusion of Undocumented Features
- CVE-2026-24714 — Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telne
- CVE-2025-41756 — Arbitrary Write with ubr-editfile
- CVE-2025-22450 — Inclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may di
- CVE-2024-52564 — Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX f
- CVE-2023-3634 — Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions
- CVE-2025-52548 — Enabling SSH and Shellinabox on the vulnerable machine
- CVE-2025-41754 — Arbitrary Read with ubr-editfile
Recently published
- CVE-2023-3634 — Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions
- CVE-2025-41756 — Arbitrary Write with ubr-editfile
- CVE-2025-41754 — Arbitrary Read with ubr-editfile
- CVE-2026-24714 — Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telne
- CVE-2025-12176 — Undocumented Administrative Accounts
- CVE-2025-55050 — CWE-1242: Inclusion of Undocumented Features
- CVE-2025-52548 — Enabling SSH and Shellinabox on the vulnerable machine
- CVE-2025-22450 — Inclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may di
- CVE-2024-52564 — Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX f