CWE-912: Hidden Functionality
The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.
75 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-34117 — Netcore / Netis Routers RCE via UDP Port 53413 Backdoor
- CVE-2026-3587 — Hidden CLI Function Allows Root Access
- CVE-2024-39754 — A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafte
- CVE-2024-5514 — MinMax CMS - Hidden Functionality
- CVE-2025-11544 — Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may c
- CVE-2024-10773 — SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for pass-the-hash attacks
- CVE-2025-30064 — Possibility to generate a session for any user via the "ex:action" parameter after obtaining access to the JWT key
- CVE-2025-0675 — Elber Communications Equipment Hidden Functionality
- CVE-2026-33280 — Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the pr
- CVE-2025-58778 — Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the
- CVE-2025-11673 — PiExtract |SOOP-CLM - Hidden Functionality
- CVE-2026-1952 — Denial of service via the undocumented subfunction in AS320T
- CVE-2026-61515 — Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
- CVE-2026-4769 — Unauthenticated Access to Internal Diagnostic Interface
- CVE-2026-18191 — Vacron|IP Camera - Hidden Functionality
- CVE-2025-1204 — The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address
- CVE-2025-0626 — Hidden Functionality vulnerability in Contec Health CMS8000 Patient Monitor
- CVE-2026-41446 — WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpoints
- CVE-2026-1741 — EFM ipTIME A8004T Debug d.cgi httpcon_check_session_url backdoor
- CVE-2024-5633 — Longse model LBH30FE200W cameras, as well as products based on this device, provide an unrestricted access for an attack
Recently published
- CVE-2026-18844 — Pulsetto Vagus Nerve Stimulator Hidden Functionality
- CVE-2026-61515 — Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
- CVE-2026-18191 — Vacron|IP Camera - Hidden Functionality
- CVE-2026-4769 — Unauthenticated Access to Internal Diagnostic Interface
- CVE-2026-7413 — Persistent undocumented backdoor access in Yarbo robot
- CVE-2026-41446 — WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpoints
- CVE-2026-1952 — Denial of service via the undocumented subfunction in AS320T
- CVE-2026-34769 — Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
- CVE-2026-4621 — Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.
- CVE-2026-33280 — Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the pr
- CVE-2026-31847 — Hidden Functionality Enables Remote Telnet Activation via /goform/setSysTools in Nexxt Nebula 300+
- CVE-2026-3587 — Hidden CLI Function Allows Root Access
- CVE-2025-48418 — A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, F
- CVE-2026-1741 — EFM ipTIME A8004T Debug d.cgi httpcon_check_session_url backdoor
- CVE-2025-55704 — Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to
- CVE-2025-11544 — Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may c
- CVE-2025-62773 — Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.
- CVE-2025-58778 — Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the
- CVE-2025-11673 — PiExtract |SOOP-CLM - Hidden Functionality
- CVE-2025-55075 — Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled