CWE-912
Allowed-with-ReviewHidden Functionality
Abstraction: Class · Status: Incomplete
The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.
160 vulnerabilities reference this CWE, most recent first.
GHSA-J3W3-RRQQ-MPX3
Vulnerability from github – Published: 2023-01-26 21:30 – Updated: 2024-11-12 00:30A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects all Solar-Log devices that use firmware version v4.2.7 up to v5.1.1 (included).
{
"affected": [],
"aliases": [
"CVE-2022-47767"
],
"database_specific": {
"cwe_ids": [
"CWE-912"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-01-26T21:18:00Z",
"severity": "CRITICAL"
},
"details": "A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects all Solar-Log devices that use firmware version v4.2.7 up to v5.1.1 (included).",
"id": "GHSA-j3w3-rrqq-mpx3",
"modified": "2024-11-12T00:30:35Z",
"published": "2023-01-26T21:30:20Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47767"
},
{
"type": "WEB",
"url": "https://www.solar-log.com/en/support/firmware-database-1"
},
{
"type": "WEB",
"url": "https://www.swascan.com/security-advisory-solar-log"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-J6RH-H9WC-GH7J
Vulnerability from github – Published: 2022-05-24 17:27 – Updated: 2022-10-15 12:00The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as root on the device on the N-Tron 702-W / 702M12-W (all versions).
{
"affected": [],
"aliases": [
"CVE-2020-16204"
],
"database_specific": {
"cwe_ids": [
"CWE-912"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2020-09-01T21:15:00Z",
"severity": "HIGH"
},
"details": "The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as root on the device on the N-Tron 702-W / 702M12-W (all versions).",
"id": "GHSA-j6rh-h9wc-gh7j",
"modified": "2022-10-15T12:00:56Z",
"published": "2022-05-24T17:27:05Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-16204"
},
{
"type": "WEB",
"url": "https://us-cert.cisa.gov/ics/advisories/icsa-20-240-01"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/159064/Red-Lion-N-Tron-702-W-702M12-W-2.0.26-XSS-CSRF-Shell.html"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2020/Sep/6"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-J9CW-5CPJ-9QJ5
Vulnerability from github – Published: 2023-03-07 00:30 – Updated: 2023-03-13 22:06In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
{
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"events": [
{
"introduced": "3.11.0-beta"
},
{
"fixed": "3.11.1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"events": [
{
"introduced": "3.10.0-beta"
},
{
"fixed": "3.10.5"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.9.8"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2021-36403"
],
"database_specific": {
"cwe_ids": [
"CWE-912"
],
"github_reviewed": true,
"github_reviewed_at": "2023-03-08T00:16:56Z",
"nvd_published_at": "2023-03-06T23:15:00Z",
"severity": "MODERATE"
},
"details": "In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.",
"id": "GHSA-j9cw-5cpj-9qj5",
"modified": "2023-03-13T22:06:44Z",
"published": "2023-03-07T00:30:25Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-36403"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=424809"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"type": "CVSS_V3"
}
],
"summary": "Moodle has a Hidden Functionality vulnerability"
}
GHSA-JFWF-RFMG-7F8M
Vulnerability from github – Published: 2025-03-08 21:30 – Updated: 2025-03-11 18:32Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
{
"affected": [],
"aliases": [
"CVE-2025-27840"
],
"database_specific": {
"cwe_ids": [
"CWE-912"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-08T20:15:36Z",
"severity": "MODERATE"
},
"details": "Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).",
"id": "GHSA-jfwf-rfmg-7f8m",
"modified": "2025-03-11T18:32:12Z",
"published": "2025-03-08T21:30:52Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27840"
},
{
"type": "WEB",
"url": "https://cheriot.org/auditing/backdoor/2025/03/09/no-esp32-style-backdoor.html"
},
{
"type": "WEB",
"url": "https://darkmentor.com/blog/esp32_non-backdoor"
},
{
"type": "WEB",
"url": "https://flyingpenguin.com/?p=67838"
},
{
"type": "WEB",
"url": "https://github.com/TarlogicSecurity/Talks/blob/main/2025_RootedCon_BluetoothTools.pdf"
},
{
"type": "WEB",
"url": "https://github.com/em0gi/CVE-2025-27840"
},
{
"type": "WEB",
"url": "https://github.com/esphome/esphome/discussions/8382"
},
{
"type": "WEB",
"url": "https://github.com/orgs/espruino/discussions/7699"
},
{
"type": "WEB",
"url": "https://news.ycombinator.com/item?id=43301369"
},
{
"type": "WEB",
"url": "https://news.ycombinator.com/item?id=43308740"
},
{
"type": "WEB",
"url": "https://reg.rootedcon.com/cfp/schedule/talk/5"
},
{
"type": "WEB",
"url": "https://www.bleepingcomputer.com/news/security/undocumented-backdoor-found-in-bluetooth-chip-used-by-a-billion-devices"
},
{
"type": "WEB",
"url": "https://www.bleepingcomputer.com/news/security/undocumented-commands-found-in-bluetooth-chip-used-by-a-billion-devices"
},
{
"type": "WEB",
"url": "https://www.espressif.com/en/news/Response_ESP32_Bluetooth"
},
{
"type": "WEB",
"url": "https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices"
},
{
"type": "WEB",
"url": "https://x.com/pascal_gujer/status/1898442439704158276"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-JM76-F53M-V476
Vulnerability from github – Published: 2023-05-22 21:30 – Updated: 2024-04-04 04:16In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appears that could allow users to execute arbitrary commands on the hub device.
{
"affected": [],
"aliases": [
"CVE-2023-25183"
],
"database_specific": {
"cwe_ids": [
"CWE-912"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-05-22T21:15:13Z",
"severity": "HIGH"
},
"details": "\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nIn Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appears that could allow users to execute arbitrary commands on the hub device.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n",
"id": "GHSA-jm76-f53m-v476",
"modified": "2024-04-04T04:16:54Z",
"published": "2023-05-22T21:30:25Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25183"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-136-01"
},
{
"type": "WEB",
"url": "https://www.control4.com/docs/product/ovrc-software/release-notes/english/latest/ovrc-software-release-notes-rev-r.pdf"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-JMVJ-M3CP-JPMF
Vulnerability from github – Published: 2023-02-22 06:30 – Updated: 2025-03-13 21:30MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.
{
"affected": [],
"aliases": [
"CVE-2023-24108"
],
"database_specific": {
"cwe_ids": [
"CWE-912"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-02-22T04:15:00Z",
"severity": "CRITICAL"
},
"details": "MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.",
"id": "GHSA-jmvj-m3cp-jpmf",
"modified": "2025-03-13T21:30:57Z",
"published": "2023-02-22T06:30:16Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24108"
},
{
"type": "WEB",
"url": "https://github.com/zetacomponents/MvcTools/issues/12"
},
{
"type": "WEB",
"url": "https://github.com/zetacomponents/MvcTools"
},
{
"type": "WEB",
"url": "https://mirrors.neusoft.edu.cn/pypi/web/simple/request"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-MCXM-8HR3-FRMX
Vulnerability from github – Published: 2024-09-04 18:30 – Updated: 2025-10-22 00:33A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to log in to an affected system by using a static administrative credential.
This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to log in to the affected system. A successful exploit could allow the attacker to log in to the affected system with administrative privileges over the API of the Cisco Smart Licensing Utility application.
{
"affected": [],
"aliases": [
"CVE-2024-20439"
],
"database_specific": {
"cwe_ids": [
"CWE-798",
"CWE-912"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-04T17:15:13Z",
"severity": "CRITICAL"
},
"details": "A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to log in to an affected system by using a static administrative credential.\n\nThis vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to log in to the affected system. A successful exploit could allow the attacker to log in to the affected system with administrative privileges over the API of the Cisco Smart Licensing Utility application.",
"id": "GHSA-mcxm-8hr3-frmx",
"modified": "2025-10-22T00:33:05Z",
"published": "2024-09-04T18:30:58Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20439"
},
{
"type": "WEB",
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-20439"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-MM4W-X64V-48CJ
Vulnerability from github – Published: 2026-08-04 15:32 – Updated: 2026-08-04 15:32Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.
{
"affected": [],
"aliases": [
"CVE-2026-61515"
],
"database_specific": {
"cwe_ids": [
"CWE-912"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-08-04T15:16:36Z",
"severity": "CRITICAL"
},
"details": "Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.",
"id": "GHSA-mm4w-x64v-48cj",
"modified": "2026-08-04T15:32:23Z",
"published": "2026-08-04T15:32:23Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61515"
},
{
"type": "WEB",
"url": "https://damiri.fr/fr/cve/CVE-2026-61515"
},
{
"type": "WEB",
"url": "https://www.puwell.com/Index/catalog"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/puwell-ip-camera-2-x-4-x-unauthenticated-command-injection-via-debugshell"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-P2HJ-VX9X-4RH8
Vulnerability from github – Published: 2026-08-13 09:31 – Updated: 2026-08-13 09:31The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).
{
"affected": [],
"aliases": [
"CVE-2026-15413"
],
"database_specific": {
"cwe_ids": [
"CWE-912"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-08-13T09:17:12Z",
"severity": "CRITICAL"
},
"details": "The Link Factory WordPress plugin is a backdoor. Distributed as a \"homepage sentence publisher\", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).",
"id": "GHSA-p2hj-vx9x-4rh8",
"modified": "2026-08-13T09:31:10Z",
"published": "2026-08-13T09:31:10Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15413"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/4cad269d-0146-4ca9-a1ae-55f02c8e5433"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-P2J3-FM26-85WV
Vulnerability from github – Published: 2025-01-30 21:31 – Updated: 2025-01-31 18:31The affected product sends out remote access requests to a hard-coded IP address, bypassing existing device network settings to do so. This could serve as a backdoor and lead to a malicious actor being able to upload and overwrite files on the device.
{
"affected": [],
"aliases": [
"CVE-2025-0626"
],
"database_specific": {
"cwe_ids": [
"CWE-912"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-30T19:15:14Z",
"severity": "HIGH"
},
"details": "The affected product sends out remote access requests to a hard-coded IP address, bypassing existing device network settings to do so. This could serve as a backdoor and lead to a malicious actor being able to upload and overwrite files on the device.",
"id": "GHSA-p2j3-fm26-85wv",
"modified": "2025-01-31T18:31:05Z",
"published": "2025-01-30T21:31:21Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0626"
},
{
"type": "WEB",
"url": "https://www.bleepingcomputer.com/news/security/backdoor-found-in-two-healthcare-patient-monitors-linked-to-ip-in-china"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/resources-tools/resources/contec-cms8000-contains-backdoor"
},
{
"type": "WEB",
"url": "https://www.fda.gov/medical-devices/safety-communications/cybersecurity-vulnerabilities-certain-patient-monitors-contec-and-epsimed-fda-safety-communication"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
Mitigation
Always verify the integrity of the product that is being installed.
CAPEC-133: Try All Common Switches
An attacker attempts to invoke all common switches and options in the target application for the purpose of discovering weaknesses in the target. For example, in some applications, adding a --debug switch causes debugging information to be displayed, which can sometimes reveal sensitive processing or configuration information to an attacker. This attack differs from other forms of API abuse in that the attacker is indiscriminately attempting to invoke options in the hope that one of them will work rather than specifically targeting a known option. Nonetheless, even if the attacker is familiar with the published options of a targeted application this attack method may still be fruitful as it might discover unpublicized functionality.
CAPEC-190: Reverse Engineer an Executable to Expose Assumed Hidden Functionality
An attacker analyzes a binary file or executable for the purpose of discovering the structure, function, and possibly source-code of the file by using a variety of analysis techniques to effectively determine how the software functions and operates. This type of analysis is also referred to as Reverse Code Engineering, as techniques exist for extracting source code from an executable. Several techniques are often employed for this purpose, both black box and white box. The use of computer bus analyzers and packet sniffers allows the binary to be studied at a level of interactions with its computing environment, such as a host OS, inter-process communication, and/or network communication. This type of analysis falls into the 'black box' category because it involves behavioral analysis of the software without reference to source code, object code, or protocol specifications.