The device includes chicken bits or undocumented features that can create entry points for unauthorized actors.
Volume of CVEs assigned to CWE-1242 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12176CRITICAL Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 | Oct 24, 2025 | 9.8 | 32 | NO | NO |
CVE-2017-20204CRITICAL DBLTek GoIP devices (models GoIP 1, 4, 8, 16, and 32) contain an undocumented vendor backdoor in the Telnet administrative interface that allows remote authentication as an undocum | Oct 15, 2025 | 9.3 | 29 | NO | NO |
CVE-2025-55050CRITICAL CWE-1242: Inclusion of Undocumented Features | Sep 9, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-3634HIGH In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of undocumented test mode which could lead to a complete loss of | Apr 16, 2026 | 8.8 | 28 | NO | NO |
CVE-2021-4469HIGH Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint without authentication. While the primary web interface on | Nov 14, 2025 | 8.7 | 27 | NO | NO |
CVE-2025-41756HIGH A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the system. | Mar 9, 2026 | 8.1 | 24 | NO | NO |
CVE-2026-24714HIGH Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telnet service on the box. | Jan 30, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-41754MEDIUM A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to read arbitrary files on the system. | Mar 9, 2026 | 6.5 | 23 | NO | NO |
CVE-2024-52564HIGH Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may disable | Dec 5, 2024 | 7.5 | 23 | NO | NO |
CVE-2025-22450HIGH Inclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may disable the LAN-side firewall function of the affected product | Jan 22, 2025 | 7.5 | 21 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.