CWE-489— Active Debug Code
The product is released with debugging code still enabled or active.— MITRE CWE catalog
102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-489page 1 of 3
- CVE-2023-4804CRITICALCVSS 9.8EG 10.02023-11-10
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
- CVE-2026-53952CRITICALCVSS 9.8EG 9.82026-09-11
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to cr…
- CVE-2026-59092CRITICALCVSS 9.8EG 9.82026-07-02
JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the…
- CVE-2026-49188CRITICALCVSS 9.8EG 9.82026-06-04
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
- CVE-2024-9644CRITICALCVSS 9.8EG 9.82025-02-04
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the administrative web server. Authentication is not enforced on some administrative functionality when using the "bapply.cgi" en…
- CVE-2024-9643CRITICALCVSS 9.8EG 9.82025-02-04
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via craf…
- CVE-2024-46873CRITICALCVSS 9.8EG 9.82024-12-23
Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege by a remote unauthenticated attacker.
- CVE-2024-21785CRITICALCVSS 9.8EG 9.82024-05-28
A leftover debug code vulnerability exists in the Telnet Diagnostic Interface functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted series of network requests can lead to unauthorized access. An attacker can send a sequen…
- CVE-2024-32047CRITICALCVSS 9.8EG 9.82024-05-15
Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining access to the testing or production server.
- CVE-2024-28008CRITICALCVSS 9.8EG 9.82024-03-28
Active Debug Code in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP…
- CVE-2023-34346CRITICALCVSS 9.8EG 9.82023-10-11
A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger t…
- CVE-2023-32645CRITICALCVSS 9.8EG 9.82023-10-11
A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger …
- CVE-2022-45677CRITICALCVSS 9.8EG 9.82023-02-21
SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php.
- CVE-2023-22357CRITICALCVSS 9.8EG 9.82023-01-17
Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being executed without authentication. A remote unauthenticated attacker may read/write in arbitrary area of t…
- CVE-2022-29520CRITICALCVSS 9.8EG 9.82022-10-25
An OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send an XM…
- CVE-2022-32585CRITICALCVSS 9.8EG 9.82022-06-30
A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vuln…
- CVE-2019-10939CRITICALCVSS 9.8EG 9.82020-04-14
A vulnerability has been identified in TIM 3V-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE Advanced (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.3), TIM…
- CVE-2026-100102CRITICALCVSS 9.5EG 9.52026-10-05
Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to c…
- CVE-2026-102628CRITICALCVSS 9.3EG 9.32026-10-01
The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled excep…
- CVE-2026-103475CRITICALCVSS 9.1EG 9.12026-09-30
yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensit…
- CVE-2026-40035CRITICALCVSS 9.1EG 9.12026-04-08
Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-empt…
- CVE-2026-77545CRITICALCVSS 9.0EG 9.02026-08-26
A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or ins…
- CVE-2026-13313HIGHCVSS 8.9EG 8.92026-10-01
An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root pr…
- CVE-2025-4106HIGHCVSS 8.9EG 8.92025-10-24
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagn…
- CVE-2026-66405HIGHCVSS 8.8EG 8.82026-08-10
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.
- CVE-2026-58378HIGHCVSS 8.8EG 8.82026-07-09
Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access.
- CVE-2025-2486HIGHCVSS 8.8EG 8.82025-11-26
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shel…
- CVE-2024-36475HIGHCVSS 8.8EG 8.82024-07-17
FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and …
- CVE-2024-31406HIGHCVSS 8.8EG 8.82024-04-24
Active debug code vulnerability exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent unauthenticated attacker with access to the device may perform unauthorized operations.
- CVE-2022-38715HIGHCVSS 8.8EG 8.82023-01-26
A leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trig…
- CVE-2022-30543HIGHCVSS 8.8EG 8.82022-11-09
A leftover debug code vulnerability exists in the console infct functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to execution of privileged operations. An attacker can send a seq…
- CVE-2022-28689HIGHCVSS 8.8EG 8.82022-11-09
A leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of request…
- CVE-2022-25995HIGHCVSS 8.8EG 8.82022-05-12
A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to…
- CVE-2021-33591HIGHCVSS 8.8EG 8.82021-05-28
An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
- CVE-2020-5763HIGHCVSS 8.8EG 8.82020-07-29
Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt.
- CVE-2020-5756HIGHCVSS 8.8EG 8.82020-07-17
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.
- CVE-2020-8477HIGHCVSS 8.8EG 8.82020-04-22
The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead…
- CVE-2017-5259HIGHCVSS 8.8EG 8.82017-12-20
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp.
- CVE-2026-66787HIGHCVSS 5.4EG 8.72026-08-20
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster …
- CVE-2025-36899HIGHCVSS 8.4EG 8.42025-09-04
There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo…
- CVE-2023-0954HIGHCVSS 8.3EG 8.32023-06-08
A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack.
- CVE-2026-84486HIGHCVSS 8.2EG 8.22026-09-23
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) and…
- CVE-2026-6485HIGHCVSS 8.2EG 8.22026-09-09
UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
- CVE-2022-20649HIGHCVSS 8.1EG 8.12024-11-15
A vulnerability in Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges in the context of the configured container…
- CVE-2022-29888HIGHCVSS 8.1EG 8.12022-11-09
A leftover debug code vulnerability exists in the httpd port 4444 upload.cgi functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can send an HTTP request t…
- CVE-2018-5454HIGHCVSS 8.1EG 8.12018-03-26
Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability where code debugging methods are enabled, which could allow an attacker to remotely execute arbitrary code during runtime.
- CVE-2025-64983HIGHCVSS 8.0EG 8.02025-11-26
Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attacker to connect via Telnet and gain access to the device.
- CVE-2025-30185HIGHCVSS 7.9EG 7.92025-11-11
Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable da…
- CVE-2024-44092HIGHCVSS 7.8EG 7.82024-09-13
There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- CVE-2026-9133HIGHCVSS 7.7EG 7.72026-05-20
Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to pe…
Map vulnerabilities like CWE-489 to your infrastructure
EchelonGraph correlates every CVE — across CWE-489 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →