CWE-489
84 CVEs • Abstraction: Base
Active Debug Code
The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.
CVEs (84)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a...Show more |
A leftover debug code vulnerability exists in the console verify functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker c...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A denial of service vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to denial of service. An attacker can send a...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An atta...Show more |
Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation settings. These compiler settings greatly decrease the level of effort for a threat actor to reverse e...Show more |
1Omron 52Nj Pa3001 Firmware Nj Pd3001 FirmwareNj101 1000 Firmware+49 moreJun 17, 2026 Jul 4, 2022 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine au...Show more |
A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests t...Show more |
A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequ...Show more |
1Lenovo 105Ideapad 3 14ada05 Firmware Ideapad 3 14ada6 FirmwareIdeapad 3 14alc6 Firmware+102 moreJun 17, 2026 Apr 22, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure b...Show more |
1Lenovo 73Ideapad 3 14ada05 Firmware Ideapad 3 14ada6 FirmwareIdeapad 3 14alc6 Firmware+70 moreJun 17, 2026 Apr 22, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to...Show more |
1Bbraun 2Datamodule Compactplus SpacecomJun 17, 2026 Apr 14, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and A11 and earlier enables attackers in possession of cryptographic material to access the device as r...Show more |
A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of network requests can lead to arbitrary firmware update. An attacker can send a sequenc...Show more |
1Bosch 2Bosch Video Management System Video Recording ManagerJun 17, 2026 Dec 8, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affe...Show more |
An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page. |
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with high privileges or an unauthenticated attacker with physical access to the device to open a debugging console. The vulnerability...Show more |
A vulnerability in the boot logic of Cisco IOS XE Software could allow an authenticated, local attacker with level 15 privileges or an unauthenticated attacker with physical access to execute arbitrary code on the underl...Show more |
A vulnerability in the dragonite debugger of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege. The vulnerability is due to the presence of developme...Show more |
1Grandstream 6Ht801 Firmware Ht802 FirmwareHt812 Firmware+3 moreJun 17, 2026 Jul 29, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt. |
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the...Show more |
1Lenovo 100Thinkpad 11e Firmware Thinkpad 11e Yoga Gen 6 FirmwareThinkpad 13 2nd Gen Firmware+97 moreJun 17, 2026 Jun 9, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. |