VYPR

CWE-912

Hidden Functionality

ClassIncomplete

Description

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.

Hidden functionality can take many forms, such as intentionally malicious code, "Easter Eggs" that contain extraneous functionality such as games, developer-friendly shortcuts that reduce maintenance or support costs such as hard-coded accounts, etc. From a security perspective, even when the functionality is not intentionally malicious or damaging, it can increase the product's attack surface and expose additional weaknesses beyond what is already exposed by the intended functionality. Even if it is not easily accessible, the hidden functionality could be useful for attacks that modify the control flow of the application.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-133 · CAPEC-190

CVEs mapped to this weakness (86)

page 1 of 5
  • CVE-2024-20439CriKEVSep 4, 2024
    risk 0.83cvss 9.8epss 0.92

    A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative…

  • CVE-2010-20103CriAug 20, 2025
    risk 0.67cvss 9.8epss 0.05

    A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root…

  • CVE-2011-10018CriAug 13, 2025
    risk 0.67cvss 9.8epss 0.02

    myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting payloads into a specially crafted collapsed cookie. This vulnerability was introduced during packaging…

  • CVE-2026-14812CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.01

    The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an…

  • CVE-2026-11976CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.00

    The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct…

  • CVE-2026-3587CriMar 23, 2026
    risk 0.65cvss 10.0epss 0.01

    An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.

  • CVE-2025-34117CriJul 16, 2025
    risk 0.65cvss epss 0.20

    A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the presence of an undocumented backdoor listener on UDP port 53413. Exact version boundaries remain undocumented. An unauthenticated…

  • CVE-2024-39754CriJan 14, 2025
    risk 0.65cvss 10.0epss 0.01

    A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network packets can lead to root access. An attacker can send packets to trigger this vulnerability.

  • CVE-2021-24867CriFeb 21, 2022
    risk 0.65cvss 9.8epss 0.19

    Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were…

  • CVE-2026-17032CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

  • CVE-2026-61515CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.02

    Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567.…

  • CVE-2026-41446CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.00

    Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical device label. Attackers with…

  • CVE-2026-1952CriApr 24, 2026
    risk 0.64cvss 9.8epss 0.00

    Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.

  • CVE-2026-33280CriMar 27, 2026
    risk 0.64cvss 9.8epss 0.00

    Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.

  • CVE-2024-45697CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS commands using hard-coded credentials.

  • CVE-2024-5514CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.01

    MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend…

  • CVE-2024-28011CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Hidden Functionality vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP,…

  • CVE-2023-24108CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.

  • CVE-2022-47767CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.01

    A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects Solar-Log devices that use firmware version v4.2.7 up to v5.1.1 (included). This does not exist in SL 200, 500, 1000 / fixed in 4.2.8…

  • CVE-2022-46997CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.