Skip to main content

CWE archive

CWE-912 CVEs

Programmatic archive

81 CVEs tagged with CWE-91228 Critical, 24 High, 24 Medium, 5 Low, 0 Unrated.

CVE-2026-18191

Published Jul 29, 2026

VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administr…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-4769

Published Jul 13, 2026

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented a…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-41446

Published Apr 28, 2026

Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-34769

Published Apr 4, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumente…

CVSS 7.7 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-3587

Published Mar 23, 2026

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-30704

Published Mar 18, 2026

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-1741

Published Feb 2, 2026

A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This…

CVSS 6.6 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-55704

Published Jan 29, 2026

Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to obtain the logs of the affected product and obtain sensitiv…

CVSS 6.9 · Medium

CVE-2025-11544

Published Dec 22, 2025

Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized firmware.

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-62773

Published Oct 22, 2025

Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.

CVSS 2.4 · Low

CVE-2025-58778

Published Oct 16, 2025

Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the manual, and enabled in the initial configuration. Anyone w…

CVSS 8.6 · High

CVE-2025-11673

Published Oct 13, 2025

SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploit a hidden functionality to execute arbitrary code on the s…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-55075

Published Sep 17, 2025

Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled by a remote authenticated attacker.

CVSS 6.9 · Medium

CVE-2025-30064

Published Aug 27, 2025

An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was…

CVSS 8.8 · High

CVE-2025-9382

Published Aug 24, 2025

A weakness has been identified in FNKvision Y215 CCTV Camera 10.194.120.40. This vulnerability affects unknown code of the file s1_rf_test_config of the component Telnet Sevice. E…

CVSS 4.5 · Medium

CVE-2010-20103

Published Aug 20, 2025

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command…

CVSS 9.3 · Critical
evidence mentions
8
Buzz score
42.0
Vendor/product tagsBeta · best-effort

CVE-2025-8938

Published Aug 14, 2025

A vulnerability was found in TOTOLINK N350R 1.2.3-B20130826. This issue affects the function formSysTel of the file /boafrm/formSysTel of the component Telnet Service. The manipul…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-10018

Published Aug 13, 2025

myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting payl…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-46267

Published Jul 22, 2025

Hidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited, the product's hidden debug function may be enabled by a remote attacker who can log in to WebGUI.

CVSS 6.9 · Medium
Showing 1-25 of 81 CVEsPage 1 of 4