CWE-489
84 CVEs • Abstraction: Base
Active Debug Code
The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.
CVEs (84)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Hard-coded credentials for the
CyberPower PowerPanel test server can be found in the
production code. This might result in an attacker gaining access to the
testing or production server. |
Active debug code vulnerability exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent unauthenticated attacker with access to the device may perform unauthorized operations. |
1Planex 2Mzk Mf300hp2 Firmware Mzk Mf300n FirmwareJun 17, 2026 Apr 15, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Active debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug function accesses the device's management page, an unintended operation may be perf...Show more |
1Nec 59Aterm Cr2500p Firmware Aterm Mr01ln FirmwareAterm Mr02ln Firmware+56 moreJun 17, 2026 Mar 28, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Active Debug Code in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2,...Show more |
1Johnsoncontrols 6Quantum Hd Unity Acuair Firmware Quantum Hd Unity Compressor FirmwareQuantum Hd Unity Condenser/vessel Firmware+3 moreJun 17, 2026 Nov 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed. |
A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108. A specially crafted network packet can lead to command execution. An attacker can send a network r...Show more |
A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network...Show more |
A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to potentially gain unauthorized access to the product. This cou...Show more |
1Johnsoncontrols 2Illustra Pro Gen 4 Dome Firmware Illustra Pro Gen 4 Ptz FirmwareJun 17, 2026 Jun 8, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack. |
1Mitsubishielectric 1Melsec Ws0 Geth00200 Firmware Jun 17, 2026 May 19, 2023 N/A· v4 8.6 HIGH· v3 N/A· v2 Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior allows a remote unauthenticated attacker to bypass authentication and illegally log into...Show more |
Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level. |
A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the follow...Show more |
1Tuition Management System Project 1Tuition Management System Jun 17, 2026 Feb 21, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php. |
1Mitsubishielectric 51Rh 12fh55 Firmware Rh 12fh70 FirmwareRh 12fh85 Firmware+48 moreJun 17, 2026 Feb 2, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authen...Show more |
A leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an H...Show more |
Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being executed without authentication. A remote unauthenticated attacker may read/write in...Show more |
The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes network checks for monitoring remote targets. Users running the Synthetic Monitoring agent prior to...Show more |
A leftover debug code vulnerability exists in the console infct functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to execution of privileged operations. An atta...Show more |
A leftover debug code vulnerability exists in the httpd port 4444 upload.cgi functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can sen...Show more |
A leftover debug code vulnerability exists in the console nvram functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker ca...Show more |