An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, l
The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the pr
Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.
Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints th
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startu
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allo
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allo
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hard
Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.0
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authen
A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, F
A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the f
Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.
Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to
Frequently Asked Questions
What is CWE-912?
CWE-912 (CWE-912) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-912?
There are 20 CVE records associated with CWE-912 in our database. Of these, 12 are critical severity, 4 are high severity, and 4 are medium severity.
How can I protect against CWE-912 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-912 using AI-powered security agents.
Detect CWE-912 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-912 vulnerabilities across your infrastructure.
Get Started