CWE-912

Hidden Functionality

Parent: CWE-684 - Incorrect Provision of Specified Functionality

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.

79 vulnerabilities with CWE-912
CVE-2026-7413 HIGH
Persistent undocumented backdoor access in Yarbo robot
CVSS 7.2
CVE-2026-41446 CRITICAL
WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpoints
CVSS 9.8
CVE-2026-1952 CRITICAL
Denial of service via the undocumented subfunction in AS320T
CVSS 9.8
CVE-2026-34769 HIGH
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
CVSS 7.7
CVE-2026-4621 MEDIUM
NEC Aterm W1200EX(-MS) - Hidden Functionality
CVSS 5.6
CVE-2026-33280 CRITICAL
BUFFALO Wi-Fi router - Command Injection
CVSS 9.8
CVE-2026-31847 HIGH
Hidden functionality allows remote Telnet enablement in Nexxt Nebula 300+
CVSS 8.8
CVE-2026-3587 CRITICAL
Hidden CLI Function Allows Root Access
CVSS 10.0
CVE-2026-30704 CRITICAL
WiFi Extender WDR201A HW V2.1 FW LFMZX28040922V1.02 - Info Disclosure
CVSS 9.1
CVE-2026-1741 MEDIUM
ipTIME A8004T 14.18.2 - Backdoor via Debug Interface cmd Argument
CVSS 6.6
CVE-2025-48418 MEDIUM
Fortinet FortiAnalyzer/FortiManager - Auth Bypass
CVSS 6.7
CVE-2025-55704 MEDIUM
Brother and Konica Minolta MFPs - Hidden Functionality Information Disclosure
CVSS 5.3
CVE-2025-11544 CRITICAL
Sharp Display Solutions - Code Injection
CVE-2025-62773 LOW
Mercku M6a <= 2.1.0 - Authenticated TELNET Access via router.telnet.enabled.update
CVSS 2.4
CVE-2025-58778 HIGH
Ruijie Networks RG-EST300 - Info Disclosure/Privilege Escalation
CVSS 7.2
CVE-2025-11673 HIGH
SOOP-CLM 5.2-5.3 - Hidden Functionality Code Execution
CVSS 7.2
CVE-2025-55075 MEDIUM
I-O DATA DEVICE WN-7D36QR and WN-7D36QR/UE - Authenticated SSH Enablement via Hidden Functionality
CVSS 4.9
CVE-2025-30064 HIGH
CGM CLININET <= 2025.MS2 - Session Generation via Insufficient JWT Verification
CVE-2025-9382 MEDIUM
FNKvision Y215 CCTV Camera - Backdoor
CVSS 6.4
CVE-2025-8938 MEDIUM
TOTOLINK N350R 1.2.3-B20130826 - Backdoor
CVSS 6.3
CVE-2025-46267 MEDIUM
WRC-BE36QS-B/WRC-W701-B - Info Disclosure
CVSS 4.9
CVE-2025-34117 CRITICAL
Netcore and Netis Router Firmware - Unauthenticated Remote Code Execution via UDP Port 53413 Backdoor
CVE-2025-6839 MEDIUM
Conjure Position Department Service Quality Evaluation System <1.0....
CVSS 6.3
CVE-2025-26412 MEDIUM
SIMCom SIM7600G Modem <LE20B03SIM7600M21-A Authenticated RCE via AT Command
CVSS 6.8
CVE-2025-48416 HIGH
eCharge Hardy Barth cPH2 / cPP2 charging stations - Unauthenticated Root Access via SSH Configuration Bypass
CVSS 8.1
Details
Vulnerabilities 79