CWE-489
Active Debug Code
Description
The product is released with debugging code still enabled or active.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-121 · CAPEC-661
CVEs mapped to this weakness (93)
page 5 of 5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66787 | Med | 0.35 | 5.4 | 0.00 | Aug 20, 2026 | A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating… | ||
| CVE-2026-58191 | Med | 0.35 | 6.5 | 0.00 | Jul 8, 2026 | Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally mounts the /test/guinea-pig, /test/guinea-pig-scrollable, and /test/guinea-pig-app-banner routes, and… | ||
| CVE-2026-32662 | Med | 0.34 | 5.3 | 0.00 | Apr 3, 2026 | Development and test API endpoints are present that mirror production functionality. | ||
| CVE-2025-1479 | Med | 0.34 | 5.3 | 0.00 | May 30, 2025 | An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code. | ||
| CVE-2023-4227 | Med | 0.34 | 5.3 | 0.00 | Aug 24, 2023 | A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to potentially gain unauthorized access to the product. This could lead to security breaches, data theft, and unauthorized… | ||
| CVE-2021-1391 | Med | 0.33 | 5.1 | 0.00 | Mar 24, 2021 | A vulnerability in the dragonite debugger of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege. The vulnerability is due to the presence of development testing and verification scripts that remained on the… | ||
| CVE-2024-29075 | Med | 0.30 | 4.6 | 0.00 | Nov 12, 2024 | Active debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain or alter the settings of the device . | ||
| CVE-2026-27131 | Med | 0.29 | 5.5 | 0.00 | Mar 23, 2026 | The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.2, admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key,… | ||
| CVE-2022-38453 | Low | 0.20 | 3.0 | 0.00 | Sep 13, 2022 | Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation settings. These compiler settings greatly decrease the level of effort for a threat actor to reverse engineer sensitive code and identify additional… | ||
| CVE-2022-27597 | Low | 0.18 | 2.7 | 0.01 | Mar 29, 2023 | A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP… | ||
| CVE-2026-65893 | Hig | 0.00 | — | 0.00 | Jul 27, 2026 | This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug… | ||
| CVE-2026-58378 | Hig | 0.00 | 8.8 | 0.00 | Jul 9, 2026 | Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access. | ||
| CVE-2025-46674 | Low | 0.00 | 3.5 | 0.01 | Apr 27, 2025 | NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle. |
- risk 0.35cvss 5.4epss 0.00
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating…
- risk 0.35cvss 6.5epss 0.00
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally mounts the /test/guinea-pig, /test/guinea-pig-scrollable, and /test/guinea-pig-app-banner routes, and…
- risk 0.34cvss 5.3epss 0.00
Development and test API endpoints are present that mirror production functionality.
- risk 0.34cvss 5.3epss 0.00
An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code.
- risk 0.34cvss 5.3epss 0.00
A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to potentially gain unauthorized access to the product. This could lead to security breaches, data theft, and unauthorized…
- risk 0.33cvss 5.1epss 0.00
A vulnerability in the dragonite debugger of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege. The vulnerability is due to the presence of development testing and verification scripts that remained on the…
- risk 0.30cvss 4.6epss 0.00
Active debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain or alter the settings of the device .
- risk 0.29cvss 5.5epss 0.00
The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.2, admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key,…
- risk 0.20cvss 3.0epss 0.00
Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation settings. These compiler settings greatly decrease the level of effort for a threat actor to reverse engineer sensitive code and identify additional…
- risk 0.18cvss 2.7epss 0.01
A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP…
- risk 0.00cvss —epss 0.00
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug…
- risk 0.00cvss 8.8epss 0.00
Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access.
- risk 0.00cvss 3.5epss 0.01
NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle.