CWE-489— Active Debug Code
The product is released with debugging code still enabled or active.— MITRE CWE catalog
102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-489page 2 of 3
- CVE-2026-66403HIGHCVSS 7.5EG 7.52026-08-10
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.
- CVE-2026-41186HIGHCVSS 7.5EG 7.52026-07-30
When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener…
- CVE-2026-45728HIGHCVSS 7.5EG 7.52026-05-19
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibly enabled. debugMode activates the Prett…
- CVE-2024-29511HIGHCVSS 7.5EG 7.52024-07-03
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use de…
- CVE-2023-1618HIGHCVSS 7.5EG 7.52023-05-19
Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior allows a remote unauthenticated attacker to bypass authentication and illegally log into the affected modul…
- CVE-2022-33323HIGHCVSS 7.5EG 7.52023-02-02
Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass thr…
- CVE-2022-32760HIGHCVSS 7.5EG 7.52022-10-25
A denial of service vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to denial of service. An attacker can send a malicious XML payl…
- CVE-2022-33971HIGHCVSS 7.5EG 7.52022-07-04
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller…
- CVE-2021-40419HIGHCVSS 7.5EG 7.52022-01-28
A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of network requests can lead to arbitrary firmware update. An attacker can send a sequence of requests to tr…
- CVE-2025-52663HIGHCVSS 7.3EG 7.32025-10-31
A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal de…
- CVE-2023-49593HIGHCVSS 7.2EG 7.22024-07-08
Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted network request can lead to arbitrary command execution.
- CVE-2024-21827HIGHCVSS 7.2EG 7.22024-06-25
A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execut…
- CVE-2022-46156HIGHCVSS 7.2EG 7.22022-11-30
The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes network checks for monitoring remote targets. Users running the Synthetic Monitoring agent prior to version 0.12.0 in t…
- CVE-2020-25156HIGHCVSS 7.2EG 7.22022-04-14
Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and A11 and earlier enables attackers in possession of cryptographic material to access the device as root.
- CVE-2026-83550HIGHCVSS 7.1EG 7.12026-10-06
A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows f…
- CVE-2026-65893HIGHCVSS 7.0EG 7.02026-07-27
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering …
- CVE-2025-15017HIGHCVSS 7.0EG 7.02025-12-31
A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical access to the device can directly connect to the UART interface and, without authentication, user inte…
- CVE-2026-33201MEDIUMCVSS 6.8EG 6.82026-03-26
Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vulnerability is exploited, files or configurations on the affected device may be read or written, or arbitrary files may …
- CVE-2025-7705MEDIUMCVSS 6.8EG 6.82025-07-22
: Active Debug Code vulnerability in ABB Switch Actuator 4 DU-83330, ABB Switch actuator, door/light 4 DU -83330-500.This issue affects Switch Actuator 4 DU-83330: All Versions; Switch actuator, door/light 4 DU -83330-500: All Versions.
- CVE-2025-2919MEDIUMCVSS 6.8EG 6.82025-03-28
A vulnerability was found in Netis WF-2404 1.1.124EN. It has been declared as critical. This vulnerability affects unknown code of the component UART. The manipulation leads to hardware allows activation of test or debug logic at runtime. …
- CVE-2024-53648MEDIUMCVSS 6.8EG 6.82025-02-11
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V9.90), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP…
- CVE-2024-41999MEDIUMCVSS 6.8EG 6.82024-09-30
Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an attacker with physical access to the device may exploit the debug function to gain access to the OS f…
- CVE-2024-7756MEDIUMCVSS 6.8EG 6.82024-09-13
A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.
- CVE-2024-30219MEDIUMCVSS 6.8EG 6.82024-04-15
Active debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug function accesses the device's management page, an unintended operation may be performed. Note that MZ…
- CVE-2021-1398MEDIUMCVSS 6.8EG 6.82021-03-24
A vulnerability in the boot logic of Cisco IOS XE Software could allow an authenticated, local attacker with level 15 privileges or an unauthenticated attacker with physical access to execute arbitrary code on the underlying Linux operatin…
- CVE-2026-81943MEDIUMCVSS 6.7EG 6.72026-09-18
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with privileged access to the device can enable th…
- CVE-2026-54799MEDIUMCVSS 6.7EG 6.72026-07-09
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's sign…
- CVE-2021-3972MEDIUMCVSS 6.7EG 6.72022-04-22
A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modi…
- CVE-2021-3971MEDIUMCVSS 6.7EG 6.72022-04-22
A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware pro…
- CVE-2026-54798MEDIUMCVSS 6.5EG 6.52026-07-09
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application includes a debugging interface that is accessible through HTTP e…
- CVE-2023-4227MEDIUMCVSS 6.5EG 6.52023-08-24
A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to potentially gain unauthorized access to the product. This could lead to security…
- CVE-2022-29481MEDIUMCVSS 6.5EG 6.52022-11-09
A leftover debug code vulnerability exists in the console nvram functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker can send a sequence o…
- CVE-2022-26023MEDIUMCVSS 6.5EG 6.52022-11-09
A leftover debug code vulnerability exists in the console verify functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker can send a sequence …
- CVE-2021-23861MEDIUMCVSS 6.5EG 6.52021-12-08
By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affects installations o…
- CVE-2020-8320MEDIUMCVSS 6.4EG 6.42020-06-09
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
- CVE-2026-100295MEDIUMCVSS 6.3EG 6.32026-09-29
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When activated, this interface allows actions that co…
- CVE-2026-50228MEDIUMCVSS 6.1EG 6.12026-09-23
An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is enabled in the produ…
- CVE-2026-58191MEDIUMCVSS 6.1EG 6.12026-07-08
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally mounts the /test/guinea-pig, /test/guinea-pig-scrollable, and /test/gu…
- CVE-2025-42872MEDIUMCVSS 6.1EG 6.12025-12-09
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session…
- CVE-2023-21496MEDIUMCVSS 6.1EG 6.12023-05-04
Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.
- CVE-2021-1381MEDIUMCVSS 6.1EG 6.12021-03-24
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with high privileges or an unauthenticated attacker with physical access to the device to open a debugging console. The vulnerability is due to insuffici…
- CVE-2026-27131MEDIUMCVSS 5.5EG 5.52026-03-23
The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.2, admin users, and users with explicit permission to access the Sprig Playground, could p…
- CVE-2025-54660MEDIUMCVSS 5.5EG 5.52025-11-18
An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve…
- CVE-2025-21472MEDIUMCVSS 5.5EG 5.52025-08-06
Information disclosure while capturing logs as eSE debug messages are logged.
- CVE-2026-32662MEDIUMCVSS 5.3EG 5.32026-04-03
Development and test API endpoints are present that mirror production functionality.
- CVE-2025-1479MEDIUMCVSS 5.3EG 5.32025-05-30
An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code.
- CVE-2021-1391MEDIUMCVSS 5.1EG 5.12021-03-24
A vulnerability in the dragonite debugger of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege. The vulnerability is due to the presence of development testing and veri…
- CVE-2024-29075MEDIUMCVSS 4.6EG 4.62024-11-12
Active debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain or alter the settings of the device .
- CVE-2022-38453MEDIUMCVSS 3.0EG 4.42022-09-13
Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation settings. These compiler settings greatly decrease the level of effort for a threat actor to reverse engineer sensitive c…
- CVE-2022-27597MEDIUMCVSS 2.7EG 4.32023-03-29
A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating …
Map vulnerabilities like CWE-489 to your infrastructure
EchelonGraph correlates every CVE — across CWE-489 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →