VYPR

CWE-1242

Inclusion of Undocumented Features or Chicken Bits

BaseIncomplete

Description

The device includes chicken bits or undocumented features that can create entry points for unauthorized actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-212 · CAPEC-36

CVEs mapped to this weakness (14)

  • CVE-2025-12176CriOct 24, 2025
    risk 0.64cvss 9.8epss 0.00

    Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2025-55050CriSep 9, 2025
    risk 0.64cvss 9.8epss 0.00

    CWE-1242: Inclusion of Undocumented Features

  • CVE-2017-20204CriOct 15, 2025
    risk 0.61cvss epss 0.01

    DBLTek GoIP devices (models GoIP 1, 4, 8, 16, and 32) contain an undocumented vendor backdoor in the Telnet administrative interface that allows remote authentication as an undocumented user via a proprietary challenge–response scheme which is fundamentally flawed. Because the…

  • CVE-2023-3634HigApr 16, 2026
    risk 0.57cvss 8.8epss 0.01

    In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of undocumented test mode which could lead to a complete loss of confidentiality, integrity and availability.

  • CVE-2021-4469HigNov 14, 2025
    risk 0.57cvss epss 0.01

    Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint without authentication. While the primary web interface on port 80 enforces authentication, the backdoor service allows any remote attacker to retrieve image…

  • CVE-2025-41756HigMar 9, 2026
    risk 0.53cvss 8.1epss 0.00

    A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the system.

  • CVE-2026-24714HigJan 30, 2026
    risk 0.49cvss 7.5epss 0.00

    Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telnet service on the box.

  • CVE-2025-22450HigJan 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Inclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may disable the LAN-side firewall function of the affected products, and open specific ports.

  • CVE-2024-52564HigDec 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may disable the firewall function of the affected products. As a result, an arbitrary OS command may be…

  • CVE-2024-54457HigDec 18, 2024
    risk 0.47cvss 7.2epss 0.00

    Inclusion of undocumented features or chicken bits issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier, which may allow a logged-in user to enable telnet service.

  • CVE-2025-41754MedMar 9, 2026
    risk 0.42cvss 6.5epss 0.00

    A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to read arbitrary files on the system.

  • CVE-2024-7011MedSep 27, 2024
    risk 0.42cvss 6.5epss 0.00

    Sharp NEC Projectors (NP-CB4500UL, NP-CB4500WL, NP-CB4700UL, NP-P525UL, NP-P525UL+, NP-P525ULG, NP-P525ULJL, NP-P525WL, NP-P525WL+, NP-P525WLG, NP-P525WLJL, NP-CG6500UL, NP-CG6500WL, NP-CG6700UL, NP-P605UL, NP-P605UL+, NP-P605ULG, NP-P605ULJL, NP-CA4120X, NP-CA4160W, NP-CA4160X,…

  • CVE-2024-2103MedApr 4, 2024
    risk 0.42cvss 6.5epss 0.00

    Inclusion of undocumented features vulnerability accessible when logged on with a privileged access level on the following Schweitzer Engineering Laboratories relays could allow the relay to behave unpredictably: SEL-700BT Motor Bus Transfer Relay, SEL-700G Generator Protection…

  • CVE-2025-52548MedSep 2, 2025
    risk 0.32cvss 4.9epss 0.00

    E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable…