Skip to content
Noroxi

CWE-489 · 87 records

Active Debug Code

CVEs in this class

88 records

  • A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108.

    CriticalCVSS 9.8No exploitEPSS 54%

    yifanwireless · yf325 firmwareOct 11, 2023

  • In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available u

    HighCVSS 8.8WeaponizedEPSS 32%

    cambiumnetworks · cnpilot r190v firmwareDec 20, 2017

  • Four-Faith F3x36 Hidden Debug Credentials

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    four-faith · f3x36 firmwareFeb 4, 2025

  • A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0.

    CriticalCVSS 9.8No exploitEPSS 3%

    robustel · r1510 firmwareJun 30, 2022

  • An OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc.

    CriticalCVSS 9.8No exploitEPSS 3%

    goabode · iota all-in-one security kit firmwareOct 25, 2022

  • A leftover debug code vulnerability exists in the Telnet Diagnostic Interface functionality of AutomationDirect P3-550E 1.2.10.9.

    CriticalCVSS 9.8No exploitEPSS 2%

    automationdirect · p3-550e firmwareMay 28, 2024

  • A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108.

    CriticalCVSS 9.8No exploitEPSS 1%

    yifanwireless · yf325 firmwareOct 11, 2023

  • Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execu

    CriticalCVSS 9.8No exploitEPSS 1%

    omron · cp1l-el20dr-d firmwareJan 17, 2023

  • A vulnerability has been identified in TIM 3V-IE (incl.

    CriticalCVSS 9.8No exploitEPSS 1%

    siemens · tim 3v-ie firmwareApr 14, 2020

  • CVE-2023-4804
    39Monitor

    An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

    CriticalCVSS 9.8No exploitEPSS 1%

    johnsoncontrols · quantum hd unity compressor firmwareNov 10, 2023

  • Multiple SHARP routers leave the hidden debug function enabled.

    CriticalCVSS 9.8No exploitEPSS 1%

    sharp corporation · home 5g hr02Dec 22, 2024

  • CVE-2023-0954
    39Monitor

    Debug feature in Sensormatic Electronics Illustra Dome and PTZ cameras

    CriticalCVSS 9.8No exploitEPSS 1%

    johnsoncontrols · illustra pro gen 4 dome firmwareJun 8, 2023

  • Active Debug Code in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-M

    CriticalCVSS 9.8No exploitEPSS 1%

    nec · aterm wg1800hp4 firmwareMar 27, 2024

  • NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading t

    CriticalCVSS 9.9No exploitEPSS 1%

    nasa · cryptolibApr 26, 2025

  • CyberPower PowerPanel business Active Debug Code

    CriticalCVSS 9.8No exploitEPSS 1%

    cyberpower · powerpanelMay 15, 2024

  • Unfurl - Werkzeug Debugger Exposure via String Config Parsing

    CriticalCVSS 9.3No exploitEPSS 1%

    ryandfir · unfurlApr 8, 2026

  • yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure

    CriticalCVSS 9.3No exploit

    yii2-starter-kit · yii2-starter-kitToday

  • Cisco Redundancy Configuration Manager Debug Remote Code Execution Vulnerability

    HighCVSS 8.1No exploitEPSS 12%

    cisco · cisco redundancy configuration managerNov 15, 2024

  • A leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020.

    HighCVSS 8.8No exploitEPSS 4%

    siretta · quartz-gold firmwareJan 26, 2023

  • CVE-2020-5763
    36Monitor

    Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service.

    HighCVSS 8.8No exploitEPSS 3%

    grandstream · ht801 firmwareJul 29, 2020

  • A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4.

    HighCVSS 8.8No exploitEPSS 3%

    inhandnetworks · ir302 firmwareMay 12, 2022

  • CVE-2020-5756
    36Monitor

    Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API

    HighCVSS 8.8No exploitEPSS 2%

    grandstream · gwn7000 firmwareJul 17, 2020

  • A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability f

    CriticalCVSS 9.0No exploitEPSS 0%

    ubiquiti inc · unifi os serverAug 26, 2026

  • An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted H

    HighCVSS 8.8No exploitEPSS 2%

    naver · comic viewerMay 28, 2021

  • A leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45.

    HighCVSS 8.8No exploitEPSS 1%

    inhandnetworks · ir302 firmwareNov 9, 2022

All vulnerability classes