The product is released with debugging code still enabled or active.
86 vulnerabilities with CWE-489
CVE-2025-1479
MEDIUM
Lenovo Legion Space <1.2.3.8/1.4.11.4 - Local Code Execution via Debug Interface
CVSS 5.3
CVE-2025-46674
LOW
NASA CryptoLib <1.3.2 - Info Disclosure
CVSS 3.5
CVE-2025-2919
MEDIUM
Netis WF-2404 1.1.124EN - Hardware Allows Activation
CVSS 6.8
CVE-2024-53648
MEDIUM
SIPROTEC 5 - Unauthenticated Remote Code Execution via Development Shell
CVSS 6.8
CVE-2024-9644
CRITICAL
Four-Faith F3x36 Firmware v2.0.0 - Authentication Bypass via bapply.cgi Endpoint
CVSS 9.8
CVE-2024-9643
CRITICAL
Four-Faith F3x36 Firmware v2.0.0 - Authentication Bypass via Hard-Coded Credentials
CVSS 9.8
CVE-2024-46873
CRITICAL
Sharp home 5G HR02 < S5.82.00 - Unauthenticated Remote Code Execution via Debug Function
CVSS 9.8
CVE-2024-29075
MEDIUM
Mesh Wi-Fi router RP562B <v1.0.2 - Info Disclosure
CVSS 4.6
CVE-2024-41999
MEDIUM
Smart-tab Android app <April 2023 - Privilege Escalation
CVSS 6.8
CVE-2024-44092
HIGH
Google Android - Local Privilege Escalation via Missing LCS Signing Enforcement
CVSS 7.8
CVE-2024-7756
MEDIUM
ThinkPad L390 Yoga & 10w Notebook - Privilege Escalation
CVSS 6.8
CVE-2024-36475
HIGH
FutureNet NXR/VXR/WXR - Authenticated OS Command Execution via Debug Function
CVSS 8.8
CVE-2024-29511
HIGH
Artifex Ghostscript <10.03.1 - Path Traversal
CVSS 7.5
CVE-2024-21827
HIGH
TP-Link ER7206 Firmware 1.4.1 Build 20240117 Rel.57421 - Remote Code Execution via CLI Server Debug Functionality
CVSS 7.2
CVE-2024-21785
CRITICAL
AutomationDirect P3-550E <1.2.10.9 - Unauthorized Access
CVSS 9.8
CVE-2024-32047
CRITICAL
CyberPower PowerPanel - Info Disclosure
CVSS 9.8
CVE-2024-31406
HIGH
RoamWiFi R10 <4.8.45 - Privilege Escalation
CVSS 8.8
CVE-2024-30219
MEDIUM
PLANEX COMMUNICATIONS - Privilege Escalation
CVSS 6.8
CVE-2024-28008
CRITICAL
NEC Corporation Various Products - Path Traversal
CVSS 9.8
CVE-2023-49593
HIGH
LevelOne WBR-6013 - Command Injection
CVSS 7.2
CVE-2023-4804
CRITICAL
Johnson Controls Quantum HD Unity Firmware 11.00-11.21 - Unauthenticated Active Debug Code Exposure
CVSS 10.0
CVE-2023-34346
CRITICAL
Yifan YF325 Firmware v1.0_20221108 - Stack-Based Buffer Overflow via httpd gwcfg.cgi
CVSS 9.8
CVE-2023-32645
CRITICAL
Yifan YF325 Firmware v1.0_20221108 - Authentication Bypass via Debug Credentials
CVSS 9.8
CVE-2023-4227
MEDIUM
ioLogik 4000 Series <1.6 - Privilege Escalation
CVSS 5.3
CVE-2023-0954
HIGH
Sensormatic Electronics Illustra Pro Gen 4 - Info Disclosure
CVSS 8.3
Details
Vulnerabilities
86