VYPR

CWE-912

Hidden Functionality

ClassIncomplete

Description

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.

Hidden functionality can take many forms, such as intentionally malicious code, "Easter Eggs" that contain extraneous functionality such as games, developer-friendly shortcuts that reduce maintenance or support costs such as hard-coded accounts, etc. From a security perspective, even when the functionality is not intentionally malicious or damaging, it can increase the product's attack surface and expose additional weaknesses beyond what is already exposed by the intended functionality. Even if it is not easily accessible, the hidden functionality could be useful for attacks that modify the control flow of the application.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-133 · CAPEC-190

CVEs mapped to this weakness (86)

page 4 of 5
  • CVE-2026-1741MedFeb 2, 2026
    risk 0.43cvss 6.6epss 0.00

    A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This manipulation of the argument cmd causes backdoor. It is possible to initiate the attack remotely.…

  • CVE-2025-2894MedMar 28, 2025
    risk 0.43cvss 6.6epss 0.01

    The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic…

  • CVE-2025-9382MedAug 24, 2025
    risk 0.42cvss 6.4epss 0.00

    A weakness has been identified in FNKvision Y215 CCTV Camera 10.194.120.40. This vulnerability affects unknown code of the file s1_rf_test_config of the component Telnet Sevice. Executing manipulation can lead to backdoor. The physical device can be targeted for the attack. This…

  • CVE-2024-37990MedSep 10, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT…

  • CVE-2023-22316MedJan 17, 2023
    risk 0.42cvss 6.5epss 0.00

    Hidden functionality vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker to access the product via undocumented Telnet or SSH services.

  • CVE-2018-17919MedOct 10, 2018
    risk 0.42cvss 6.5epss 0.01

    All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video streams.

  • CVE-2025-8938MedAug 14, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in TOTOLINK N350R 1.2.3-B20130826. This issue affects the function formSysTel of the file /boafrm/formSysTel of the component Telnet Service. The manipulation of the argument TelEnabled leads to backdoor. The attack may be initiated remotely. The…

  • CVE-2025-6839MedJun 29, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, has been found in Conjure Position Department Service Quality Evaluation System up to 1.0.11. Affected by this issue is the function eval of the file public/assets/less/bootstrap-less/mixins/head.php. The manipulation of the…

  • CVE-2023-4467MedDec 29, 2023
    risk 0.40cvss 6.2epss 0.00

    A vulnerability was found in Poly Trio 8800 7.2.6.0019 and classified as critical. Affected by this issue is some unknown functionality of the component Test Automation Mode. The manipulation leads to backdoor. It is possible to launch the attack on the physical device. The…

  • CVE-2026-4621MedMar 27, 2026
    risk 0.36cvss 5.6epss 0.00

    Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.

  • CVE-2017-20082MedJun 22, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. This issue affects some unknown processing. The manipulation leads to backdoor. The attack needs to be approached locally. The exploit has been disclosed to…

  • CVE-2020-3352MedOct 21, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands. The vulnerability is due to the presence of undocumented configuration commands. An attacker could exploit this vulnerability by…

  • CVE-2025-55704MedJan 29, 2026
    risk 0.34cvss 5.3epss 0.00

    Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to obtain the logs of the affected product and obtain sensitive information within the logs.

  • CVE-2021-36403MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.01

    In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.

  • CVE-2017-20084MedJun 22, 2022
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832 and classified as critical. Affected by this vulnerability is an unknown functionality of the component KNX Group Address. The manipulation leads to backdoor. Local access is required to approach…

  • CVE-2017-20083MedJun 22, 2022
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, was found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. Affected is an unknown function of the component SSH Server. The manipulation leads to backdoor. An attack has to be approached locally. The exploit has been disclosed…

  • CVE-2021-4229MedMay 24, 2022
    risk 0.33cvss 5.0epss 0.01

    A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the…

  • CVE-2025-55075MedSep 17, 2025
    risk 0.32cvss 4.9epss 0.00

    Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled by a remote authenticated attacker.

  • CVE-2025-46267MedJul 22, 2025
    risk 0.32cvss 4.9epss 0.00

    Hidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited, the product's hidden debug function may be enabled by a remote attacker who can log in to WebGUI.

  • CVE-2024-37994MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT…