CWE-489

Active Debug Code

Parent: CWE-710 - Improper Adherence to Coding Standards

The product is released with debugging code still enabled or active.

79 vulnerabilities with CWE-489
CVE-2024-29075 MEDIUM
Mesh Wi-Fi router RP562B <v1.0.2 - Info Disclosure
CVSS 4.6
CVE-2024-41999 MEDIUM
Smart-tab Android app <April 2023 - Privilege Escalation
CVSS 6.8
CVE-2024-44092 HIGH
Google Android - Local Privilege Escalation via Missing LCS Signing Enforcement
CVSS 7.8
CVE-2024-7756 MEDIUM
ThinkPad L390 Yoga & 10w Notebook - Privilege Escalation
CVSS 6.8
CVE-2024-36475 HIGH
FutureNet NXR/VXR/WXR - Authenticated OS Command Execution via Debug Function
CVSS 8.8
CVE-2024-29511 HIGH
Artifex Ghostscript <10.03.1 - Path Traversal
CVSS 7.5
CVE-2024-21827 HIGH
TP-Link ER7206 Firmware 1.4.1 Build 20240117 Rel.57421 - Remote Code Execution via CLI Server Debug Functionality
CVSS 7.2
CVE-2024-21785 CRITICAL
AutomationDirect P3-550E <1.2.10.9 - Unauthorized Access
CVSS 9.8
CVE-2024-32047 CRITICAL
CyberPower PowerPanel - Info Disclosure
CVSS 9.8
CVE-2024-31406 HIGH
RoamWiFi R10 <4.8.45 - Privilege Escalation
CVSS 8.8
CVE-2024-30219 MEDIUM
PLANEX COMMUNICATIONS - Privilege Escalation
CVSS 6.8
CVE-2024-28008 CRITICAL
NEC Corporation Various Products - Path Traversal
CVSS 9.8
CVE-2023-49593 HIGH
LevelOne WBR-6013 - Command Injection
CVSS 7.2
CVE-2023-4804 CRITICAL
Johnson Controls Quantum HD Unity Firmware 11.00-11.21 - Unauthenticated Active Debug Code Exposure
CVSS 10.0
CVE-2023-34346 CRITICAL
Yifan YF325 Firmware v1.0_20221108 - Stack-Based Buffer Overflow via httpd gwcfg.cgi
CVSS 9.8
CVE-2023-32645 CRITICAL
Yifan YF325 Firmware v1.0_20221108 - Authentication Bypass via Debug Credentials
CVSS 9.8
CVE-2023-4227 MEDIUM
ioLogik 4000 Series <1.6 - Privilege Escalation
CVSS 5.3
CVE-2023-0954 HIGH
Sensormatic Electronics Illustra Pro Gen 4 - Info Disclosure
CVSS 8.3
CVE-2023-1618 HIGH
Mitsubishi Electric MELSEC WS Series - Auth Bypass
CVSS 7.5
CVE-2023-21496 MEDIUM
ActivityManagerService <SMR May-2023 Release 1 - Use After Free
CVSS 6.1
CVE-2023-22357 CRITICAL
OMRON CP1L-EL20DR-D Firmware - Unauthenticated Arbitrary Memory Read/Write and Denial of Service via Active Debug Code
CVSS 9.8
CVE-2022-20649 HIGH
Cisco Redundancy Configuration Manager - Unauthenticated Remote Code Execution via Debug Mode
CVSS 8.1
CVE-2022-27597 LOW
QNAP QVR - Authenticated Out-of-bounds Read
CVSS 2.7
CVE-2022-45677 CRITICAL
Tution Management System - SQL Injection via Email Parameter
CVSS 9.8
CVE-2022-33323 HIGH
Mitsubishi Electric MELFA SD/SQ Series & F-Series - Auth Bypass
CVSS 7.5
Details
Vulnerabilities 79