VYPR

CWE-489

Active Debug Code

BaseDraft

Description

The product is released with debugging code still enabled or active.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-121 · CAPEC-661

CVEs mapped to this weakness (88)

page 3 of 5
  • CVE-2023-1618HigMay 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior allows a remote unauthenticated attacker to bypass authentication and illegally log into the affected module by connecting to it via telnet which…

  • CVE-2022-33323HigFeb 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass through an unauthorized telnet login. As…

  • CVE-2022-32760HigOct 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.

  • CVE-2022-33971HigJul 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and…

  • CVE-2021-40419HigJan 28, 2022
    risk 0.49cvss 7.5epss 0.01

    A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of network requests can lead to arbitrary firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2025-52663HigOct 31, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API. …

  • CVE-2023-49593HigJul 8, 2024
    risk 0.47cvss 7.2epss 0.01

    Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted network request can lead to arbitrary command execution.

  • CVE-2024-21827HigJun 25, 2024
    risk 0.47cvss 7.2epss 0.01

    A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of…

  • CVE-2020-25156HigApr 14, 2022
    risk 0.47cvss 7.2epss 0.01

    Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and A11 and earlier enables attackers in possession of cryptographic material to access the device as root.

  • CVE-2025-15017HigDec 31, 2025
    risk 0.46cvss epss 0.00

    A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical access to the device can directly connect to the UART interface and, without authentication, user interaction, or execution conditions, gain…

  • CVE-2026-54799MedJul 9, 2026
    risk 0.44cvss 6.7epss 0.00

    A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could…

  • CVE-2026-33201MedMar 26, 2026
    risk 0.44cvss 6.8epss 0.00

    Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vulnerability is exploited, files or configurations on the affected device may be read or written, or arbitrary files may be executed with root privileges.

  • CVE-2025-7705MedJul 22, 2025
    risk 0.44cvss 6.8epss 0.00

    : Active Debug Code vulnerability in ABB Switch Actuator 4 DU-83330, ABB Switch actuator, door/light 4 DU -83330-500.This issue affects Switch Actuator 4 DU-83330: All Versions; Switch actuator, door/light 4 DU -83330-500: All Versions.

  • CVE-2025-2919MedMar 28, 2025
    risk 0.44cvss 6.8epss 0.00

    A vulnerability was found in Netis WF-2404 1.1.124EN. It has been declared as critical. This vulnerability affects unknown code of the component UART. The manipulation leads to hardware allows activation of test or debug logic at runtime. It is possible to launch the attack on…

  • CVE-2024-53648MedFeb 11, 2025
    risk 0.44cvss 6.8epss 0.00

    A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V9.90), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions < V9.90), SIPROTEC 5…

  • CVE-2024-41999MedSep 30, 2024
    risk 0.44cvss 6.8epss 0.00

    Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an attacker with physical access to the device may exploit the debug function to gain access to the OS functions, escalate the privilege, change…

  • CVE-2024-7756MedSep 13, 2024
    risk 0.44cvss 6.8epss 0.00

    A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.

  • CVE-2024-30219MedApr 15, 2024
    risk 0.44cvss 6.8epss 0.00

    Active debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug function accesses the device's management page, an unintended operation may be performed. Note that MZK-MF300N is no longer supported,…

  • CVE-2021-3972MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.03

    A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

  • CVE-2021-3971MedApr 22, 2022
    risk 0.44cvss 6.7epss 0.01

    A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM…