CWE-489 · 87 records
Active Debug Code
CVEs in this class
88 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2023-32645No exploit | A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108.yifanwireless · yf325 firmware · CWE-489 | Critical9.8 | — | 53.8% | Oct 11, 2023 |
45Plan | CVE-2017-5259Weaponized | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available ucambiumnetworks · cnpilot r190v firmware · CWE-489 | High8.8 | — | 32.4% | Dec 20, 2017 |
40Plan | CVE-2024-9643Proof of concept | Four-Faith F3x36 Hidden Debug Credentialsfour-faith · f3x36 firmware · CWE-489 | Critical9.8 | — | 3.0% | Feb 4, 2025 |
40Plan | CVE-2022-32585No exploit | A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0.robustel · r1510 firmware · CWE-489 | Critical9.8 | — | 3.0% | Jun 30, 2022 |
40Plan | CVE-2022-29520No exploit | An OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc.goabode · iota all-in-one security kit firmware · CWE-489 | Critical9.8 | — | 2.9% | Oct 25, 2022 |
39Monitor | CVE-2024-21785No exploit | A leftover debug code vulnerability exists in the Telnet Diagnostic Interface functionality of AutomationDirect P3-550E 1.2.10.9.automationdirect · p3-550e firmware · CWE-489 | Critical9.8 | — | 1.5% | May 28, 2024 |
39Monitor | CVE-2023-34346No exploit | A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108.yifanwireless · yf325 firmware · CWE-489 | Critical9.8 | — | 1.3% | Oct 11, 2023 |
39Monitor | CVE-2023-22357No exploit | Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execuomron · cp1l-el20dr-d firmware · CWE-489 | Critical9.8 | — | 1.2% | Jan 17, 2023 |
39Monitor | CVE-2019-10939No exploit | A vulnerability has been identified in TIM 3V-IE (incl.siemens · tim 3v-ie firmware · CWE-489 | Critical9.8 | — | 1.1% | Apr 14, 2020 |
39Monitor | CVE-2023-4804No exploit | An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.johnsoncontrols · quantum hd unity compressor firmware · CWE-489 | Critical9.8 | — | 0.8% | Nov 10, 2023 |
39Monitor | CVE-2024-46873No exploit | Multiple SHARP routers leave the hidden debug function enabled.sharp corporation · home 5g hr02 · CWE-489 | Critical9.8 | — | 0.7% | Dec 22, 2024 |
39Monitor | CVE-2023-0954No exploit | Debug feature in Sensormatic Electronics Illustra Dome and PTZ camerasjohnsoncontrols · illustra pro gen 4 dome firmware · CWE-489 | Critical9.8 | — | 0.7% | Jun 8, 2023 |
39Monitor | CVE-2024-28008No exploit | Active Debug Code in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-Mnec · aterm wg1800hp4 firmware · CWE-489 | Critical9.8 | — | 0.6% | Mar 27, 2024 |
39Monitor | CVE-2025-46674No exploit | NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading tnasa · cryptolib · CWE-489 | Critical9.9 | — | 0.6% | Apr 26, 2025 |
39Monitor | CVE-2024-32047No exploit | CyberPower PowerPanel business Active Debug Codecyberpower · powerpanel · CWE-489 | Critical9.8 | — | 0.5% | May 15, 2024 |
37Monitor | CVE-2026-40035No exploit | Unfurl - Werkzeug Debugger Exposure via String Config Parsingryandfir · unfurl · CWE-489 | Critical9.3 | — | 0.7% | Apr 8, 2026 |
37Monitor | CVE-2026-103475No exploit | yii2-starter-kit through 4.2.0 Debug and Gii Module Exposureyii2-starter-kit · yii2-starter-kit · CWE-489 | Critical9.3 | — | — | Today |
36Monitor | CVE-2022-20649No exploit | Cisco Redundancy Configuration Manager Debug Remote Code Execution Vulnerabilitycisco · cisco redundancy configuration manager · CWE-489 | High8.1 | — | 12.0% | Nov 15, 2024 |
36Monitor | CVE-2022-38715No exploit | A leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020.siretta · quartz-gold firmware · CWE-489 | High8.8 | — | 3.7% | Jan 26, 2023 |
36Monitor | CVE-2020-5763No exploit | Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service.grandstream · ht801 firmware · CWE-489 | High8.8 | — | 2.7% | Jul 29, 2020 |
36Monitor | CVE-2022-25995No exploit | A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4.inhandnetworks · ir302 firmware · CWE-489 | High8.8 | — | 2.7% | May 12, 2022 |
36Monitor | CVE-2020-5756No exploit | Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented APIgrandstream · gwn7000 firmware · CWE-489 | High8.8 | — | 2.5% | Jul 17, 2020 |
36Monitor | CVE-2026-77545No exploit | A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability fubiquiti inc · unifi os server · CWE-489 | Critical9.0 | — | 0.4% | Aug 26, 2026 |
35Monitor | CVE-2021-33591No exploit | An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted Hnaver · comic viewer · CWE-489 | High8.8 | — | 1.6% | May 28, 2021 |
35Monitor | CVE-2022-28689No exploit | A leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45.inhandnetworks · ir302 firmware · CWE-489 | High8.8 | — | 1.0% | Nov 9, 2022 |
- CVE-2023-3264555Plan
A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108.
CriticalCVSS 9.8No exploitEPSS 54%yifanwireless · yf325 firmwareOct 11, 2023
- CVE-2017-525945Plan
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available u
HighCVSS 8.8WeaponizedEPSS 32%cambiumnetworks · cnpilot r190v firmwareDec 20, 2017
- CVE-2024-964340Plan
Four-Faith F3x36 Hidden Debug Credentials
CriticalCVSS 9.8Proof of conceptEPSS 3%four-faith · f3x36 firmwareFeb 4, 2025
- CVE-2022-3258540Plan
A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0.
CriticalCVSS 9.8No exploitEPSS 3%robustel · r1510 firmwareJun 30, 2022
- CVE-2022-2952040Plan
An OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc.
CriticalCVSS 9.8No exploitEPSS 3%goabode · iota all-in-one security kit firmwareOct 25, 2022
- CVE-2024-2178539Monitor
A leftover debug code vulnerability exists in the Telnet Diagnostic Interface functionality of AutomationDirect P3-550E 1.2.10.9.
CriticalCVSS 9.8No exploitEPSS 2%automationdirect · p3-550e firmwareMay 28, 2024
- CVE-2023-3434639Monitor
A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108.
CriticalCVSS 9.8No exploitEPSS 1%yifanwireless · yf325 firmwareOct 11, 2023
- CVE-2023-2235739Monitor
Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execu
CriticalCVSS 9.8No exploitEPSS 1%omron · cp1l-el20dr-d firmwareJan 17, 2023
- CVE-2019-1093939Monitor
A vulnerability has been identified in TIM 3V-IE (incl.
CriticalCVSS 9.8No exploitEPSS 1%siemens · tim 3v-ie firmwareApr 14, 2020
- CVE-2023-480439Monitor
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
CriticalCVSS 9.8No exploitEPSS 1%johnsoncontrols · quantum hd unity compressor firmwareNov 10, 2023
- CVE-2024-4687339Monitor
Multiple SHARP routers leave the hidden debug function enabled.
CriticalCVSS 9.8No exploitEPSS 1%sharp corporation · home 5g hr02Dec 22, 2024
- CVE-2023-095439Monitor
Debug feature in Sensormatic Electronics Illustra Dome and PTZ cameras
CriticalCVSS 9.8No exploitEPSS 1%johnsoncontrols · illustra pro gen 4 dome firmwareJun 8, 2023
- CVE-2024-2800839Monitor
Active Debug Code in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-M
CriticalCVSS 9.8No exploitEPSS 1%nec · aterm wg1800hp4 firmwareMar 27, 2024
- CVE-2025-4667439Monitor
NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading t
CriticalCVSS 9.9No exploitEPSS 1%nasa · cryptolibApr 26, 2025
- CVE-2024-3204739Monitor
CyberPower PowerPanel business Active Debug Code
CriticalCVSS 9.8No exploitEPSS 1%cyberpower · powerpanelMay 15, 2024
- CVE-2026-4003537Monitor
Unfurl - Werkzeug Debugger Exposure via String Config Parsing
CriticalCVSS 9.3No exploitEPSS 1%ryandfir · unfurlApr 8, 2026
- CVE-2026-10347537Monitor
yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure
CriticalCVSS 9.3No exploityii2-starter-kit · yii2-starter-kitToday
- CVE-2022-2064936Monitor
Cisco Redundancy Configuration Manager Debug Remote Code Execution Vulnerability
HighCVSS 8.1No exploitEPSS 12%cisco · cisco redundancy configuration managerNov 15, 2024
- CVE-2022-3871536Monitor
A leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020.
HighCVSS 8.8No exploitEPSS 4%siretta · quartz-gold firmwareJan 26, 2023
- CVE-2020-576336Monitor
Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service.
HighCVSS 8.8No exploitEPSS 3%grandstream · ht801 firmwareJul 29, 2020
- CVE-2022-2599536Monitor
A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4.
HighCVSS 8.8No exploitEPSS 3%inhandnetworks · ir302 firmwareMay 12, 2022
- CVE-2020-575636Monitor
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API
HighCVSS 8.8No exploitEPSS 2%grandstream · gwn7000 firmwareJul 17, 2020
- CVE-2026-7754536Monitor
A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability f
CriticalCVSS 9.0No exploitEPSS 0%ubiquiti inc · unifi os serverAug 26, 2026
- CVE-2021-3359135Monitor
An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted H
HighCVSS 8.8No exploitEPSS 2%naver · comic viewerMay 28, 2021
- CVE-2022-2868935Monitor
A leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45.
HighCVSS 8.8No exploitEPSS 1%inhandnetworks · ir302 firmwareNov 9, 2022