CWE-489

Active Debug Code

Parent: CWE-710 - Improper Adherence to Coding Standards

The product is released with debugging code still enabled or active.

86 vulnerabilities with CWE-489
CVE-2025-1479 MEDIUM
Lenovo Legion Space <1.2.3.8/1.4.11.4 - Local Code Execution via Debug Interface
CVSS 5.3
CVE-2025-46674 LOW
NASA CryptoLib <1.3.2 - Info Disclosure
CVSS 3.5
CVE-2025-2919 MEDIUM
Netis WF-2404 1.1.124EN - Hardware Allows Activation
CVSS 6.8
CVE-2024-53648 MEDIUM
SIPROTEC 5 - Unauthenticated Remote Code Execution via Development Shell
CVSS 6.8
CVE-2024-9644 CRITICAL
Four-Faith F3x36 Firmware v2.0.0 - Authentication Bypass via bapply.cgi Endpoint
CVSS 9.8
CVE-2024-9643 CRITICAL
Four-Faith F3x36 Firmware v2.0.0 - Authentication Bypass via Hard-Coded Credentials
CVSS 9.8
CVE-2024-46873 CRITICAL
Sharp home 5G HR02 < S5.82.00 - Unauthenticated Remote Code Execution via Debug Function
CVSS 9.8
CVE-2024-29075 MEDIUM
Mesh Wi-Fi router RP562B <v1.0.2 - Info Disclosure
CVSS 4.6
CVE-2024-41999 MEDIUM
Smart-tab Android app <April 2023 - Privilege Escalation
CVSS 6.8
CVE-2024-44092 HIGH
Google Android - Local Privilege Escalation via Missing LCS Signing Enforcement
CVSS 7.8
CVE-2024-7756 MEDIUM
ThinkPad L390 Yoga & 10w Notebook - Privilege Escalation
CVSS 6.8
CVE-2024-36475 HIGH
FutureNet NXR/VXR/WXR - Authenticated OS Command Execution via Debug Function
CVSS 8.8
CVE-2024-29511 HIGH
Artifex Ghostscript <10.03.1 - Path Traversal
CVSS 7.5
CVE-2024-21827 HIGH
TP-Link ER7206 Firmware 1.4.1 Build 20240117 Rel.57421 - Remote Code Execution via CLI Server Debug Functionality
CVSS 7.2
CVE-2024-21785 CRITICAL
AutomationDirect P3-550E <1.2.10.9 - Unauthorized Access
CVSS 9.8
CVE-2024-32047 CRITICAL
CyberPower PowerPanel - Info Disclosure
CVSS 9.8
CVE-2024-31406 HIGH
RoamWiFi R10 <4.8.45 - Privilege Escalation
CVSS 8.8
CVE-2024-30219 MEDIUM
PLANEX COMMUNICATIONS - Privilege Escalation
CVSS 6.8
CVE-2024-28008 CRITICAL
NEC Corporation Various Products - Path Traversal
CVSS 9.8
CVE-2023-49593 HIGH
LevelOne WBR-6013 - Command Injection
CVSS 7.2
CVE-2023-4804 CRITICAL
Johnson Controls Quantum HD Unity Firmware 11.00-11.21 - Unauthenticated Active Debug Code Exposure
CVSS 10.0
CVE-2023-34346 CRITICAL
Yifan YF325 Firmware v1.0_20221108 - Stack-Based Buffer Overflow via httpd gwcfg.cgi
CVSS 9.8
CVE-2023-32645 CRITICAL
Yifan YF325 Firmware v1.0_20221108 - Authentication Bypass via Debug Credentials
CVSS 9.8
CVE-2023-4227 MEDIUM
ioLogik 4000 Series <1.6 - Privilege Escalation
CVSS 5.3
CVE-2023-0954 HIGH
Sensormatic Electronics Illustra Pro Gen 4 - Info Disclosure
CVSS 8.3
Details
Vulnerabilities 86