VYPR

CWE-489

Active Debug Code

BaseDraft

Description

The product is released with debugging code still enabled or active.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-121 · CAPEC-661

CVEs mapped to this weakness (88)

page 2 of 5
  • CVE-2024-36475HigJul 17, 2024
    risk 0.57cvss 8.8epss 0.01

    FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and an arbitrary OS command may be executed.

  • CVE-2024-31406HigApr 24, 2024
    risk 0.57cvss 8.8epss 0.00

    Active debug code vulnerability exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent unauthenticated attacker with access to the device may perform unauthorized operations.

  • CVE-2022-38715HigJan 26, 2023
    risk 0.57cvss 8.8epss 0.04

    A leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-30543HigNov 9, 2022
    risk 0.57cvss 8.8epss 0.01

    A leftover debug code vulnerability exists in the console infct functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to execution of privileged operations. An attacker can send a sequence of requests to trigger this…

  • CVE-2022-28689HigNov 9, 2022
    risk 0.57cvss 8.8epss 0.01

    A leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2022-25995HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.03

    A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2021-33591HigMay 28, 2021
    risk 0.57cvss 8.8epss 0.02

    An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

  • CVE-2020-5763HigJul 29, 2020
    risk 0.57cvss 8.8epss 0.03

    Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt.

  • CVE-2020-5756HigJul 17, 2020
    risk 0.57cvss 8.8epss 0.02

    Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.

  • CVE-2020-8477HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.02

    The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.

  • CVE-2025-36899HigSep 4, 2025
    risk 0.55cvss 8.4epss 0.00

    There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2022-20649HigNov 15, 2024
    risk 0.54cvss 8.1epss 0.12

    A vulnerability in Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges in the context of the configured container. This vulnerability exists because…

  • CVE-2023-0954HigJun 8, 2023
    risk 0.54cvss 8.3epss 0.01

    A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack.

  • CVE-2022-29888HigNov 9, 2022
    risk 0.53cvss 8.1epss 0.01

    A leftover debug code vulnerability exists in the httpd port 4444 upload.cgi functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2018-5454HigMar 26, 2018
    risk 0.53cvss 8.1epss 0.04

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability where code debugging methods are enabled, which could allow an attacker to remotely execute arbitrary code during runtime.

  • CVE-2025-64983HigNov 26, 2025
    risk 0.52cvss 8.0epss 0.00

    Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attacker to connect via Telnet and gain access to the device.

  • CVE-2025-30185HigNov 11, 2025
    risk 0.51cvss 7.9epss 0.00

    Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable data alteration. This result may…

  • CVE-2024-44092HigSep 13, 2024
    risk 0.51cvss 7.8epss 0.00

    There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-66403HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.

  • CVE-2024-29511HigJul 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file…