Threats Tagged 'cwe-912'
View all threats tagged with 'cwe-912'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-912'
Click on any threat for detailed analysis and mitigation recommendations
0 The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check). Join the discussion | CVE Database V5 | 08/13/2026, 08:13:11 UTC Added: 08/13/2026, 08:26:39 UTC |
0 The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on. Join the discussion | CVE Database V5 | 08/11/2026, 20:03:24 UTC Added: 08/11/2026, 20:11:55 UTC |
Multiple Supsystic Pro plugins were distributed containing malicious code due to a compromise of the vendor's update server. This vulnerability allows unauthenticated attackers to deploy a second-stage payload that can exfiltrate credentials and other sensitive data, as well as gain full control over affected websites. The issue is rated critical with a CVSS score of 9.8, indicating high impact on confidentiality, integrity, and availability. Join the discussion | GCVE Database | 08/07/2026, 00:31:15 UTC Added: 08/07/2026, 05:56:53 UTC |
0 The Premium SEO WordPress plugin contains a critical vulnerability that introduces an unauthenticated backdoor. This backdoor allows attackers to create hidden administrator accounts and, in some versions, enables remote code execution, server-side request forgery, and arbitrary front-end script or content injection. These flaws give unauthenticated attackers full control over affected sites. Join the discussion | CVE Database V5 | 08/06/2026, 16:52:36 UTC Added: 08/06/2026, 22:13:07 UTC |
The MonsterInsights Pro update distribution S3 bucket was compromised, allowing an attacker to insert a malicious file into versions 10.2.0 and 10.2.2 of the software. The malicious file, class-system-check.php, was found in three variants sharing the same encryption key, indicating a single threat actor with ongoing access. This vulnerability is classified as CWE-912 (Hidden Functionality) and has a critical CVSS score of 10. The attacker retains write access to the update distribution bucket, posing a severe risk of supply chain compromise. The product is a cloud service, and a patch is available. Join the discussion | CVE Database V5 | 08/06/2026, 16:40:18 UTC Added: 08/06/2026, 22:13:07 UTC |
Vacron VIN-DS783E-E6 contains a critical hidden functionality vulnerability (CWE-912) that allows unauthenticated remote attackers to access a concealed function and obtain administrator credentials. This vulnerability has a CVSS 4.0 score of 9.3, indicating high severity and ease of exploitation without user interaction or privileges. No patch or official remediation guidance is currently available from the vendor. Join the discussion | CVE Database V5 | 07/29/2026, 06:36:50 UTC Added: 07/29/2026, 07:37:43 UTC |
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise. Join the discussion | CVE Database V5 | 07/13/2026, 06:35:01 UTC Added: 07/13/2026, 07:51:42 UTC |
0 The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly transmits the site URL, administrator email address, and license key to a third-party server. Join the discussion | CVE Database V5 | 07/10/2026, 06:00:02 UTC Added: 07/10/2026, 06:33:05 UTC |
The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers. Join the discussion | CVE Database V5 | 07/07/2026, 06:00:01 UTC Added: 07/07/2026, 06:22:09 UTC |
The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password. A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor Join the discussion | CVE Database V5 | 07/06/2026, 19:17:07 UTC Added: 07/06/2026, 19:52:08 UTC |
Showing 1 to 10 of 23 results