VYPR

CWE-489

Active Debug Code

BaseDraft

Description

The product is released with debugging code still enabled or active.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-121 · CAPEC-661

CVEs mapped to this weakness (93)

page 3 of 5
  • CVE-2024-44092HigSep 13, 2024
    risk 0.51cvss 7.8epss 0.00

    There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-59092HigJul 2, 2026
    risk 0.50cvss 7.7epss 0.00

    JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared http.DefaultServeMux. Attackers…

  • CVE-2026-66403HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.

  • CVE-2024-29511HigJul 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file…

  • CVE-2023-1618HigMay 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior allows a remote unauthenticated attacker to bypass authentication and illegally log into the affected module by connecting to it via telnet which…

  • CVE-2022-33323HigFeb 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass through an unauthorized telnet login. As…

  • CVE-2022-32760HigOct 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.

  • CVE-2022-33971HigJul 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and…

  • CVE-2021-40419HigJan 28, 2022
    risk 0.49cvss 7.5epss 0.01

    A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of network requests can lead to arbitrary firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2025-52663HigOct 31, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API. …

  • CVE-2023-49593HigJul 8, 2024
    risk 0.47cvss 7.2epss 0.01

    Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted network request can lead to arbitrary command execution.

  • CVE-2024-21827HigJun 25, 2024
    risk 0.47cvss 7.2epss 0.01

    A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of…

  • CVE-2020-25156HigApr 14, 2022
    risk 0.47cvss 7.2epss 0.01

    Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and A11 and earlier enables attackers in possession of cryptographic material to access the device as root.

  • CVE-2025-15017HigDec 31, 2025
    risk 0.46cvss —epss 0.00

    A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical access to the device can directly connect to the UART interface and, without authentication, user interaction, or execution conditions, gain…

  • CVE-2026-81943MedSep 18, 2026
    risk 0.44cvss 6.7epss 0.00

    PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with privileged access to the device can enable this debug mode to execute arbitrary code…

  • CVE-2026-54799MedJul 9, 2026
    risk 0.44cvss 6.7epss 0.00

    A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could…

  • CVE-2026-33201MedMar 26, 2026
    risk 0.44cvss 6.8epss 0.00

    Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vulnerability is exploited, files or configurations on the affected device may be read or written, or arbitrary files may be executed with root privileges.

  • CVE-2025-7705MedJul 22, 2025
    risk 0.44cvss 6.8epss 0.00

    : Active Debug Code vulnerability in ABB Switch Actuator 4 DU-83330, ABB Switch actuator, door/light 4 DU -83330-500.This issue affects Switch Actuator 4 DU-83330: All Versions; Switch actuator, door/light 4 DU -83330-500: All Versions.

  • CVE-2025-2919MedMar 28, 2025
    risk 0.44cvss 6.8epss 0.00

    A vulnerability was found in Netis WF-2404 1.1.124EN. It has been declared as critical. This vulnerability affects unknown code of the component UART. The manipulation leads to hardware allows activation of test or debug logic at runtime. It is possible to launch the attack on…

  • CVE-2024-53648MedFeb 11, 2025
    risk 0.44cvss 6.8epss 0.00

    A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V9.90), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions < V9.90), SIPROTEC 5…