CWE-489: CWE-489
Yearly Trend
Top Affected Vendors
All CWE-489 CVEs (23)
Unauthorized users can access debug features in Quantum HD Unity products that were accidentally exposed. This affects all Quantum HD Unity products w...
Nov 10, 2023The Four-Faith F3x36 router firmware v2.0.0 contains hard-coded administrative credentials, allowing attackers to bypass authentication and gain full ...
Feb 4, 2025Multiple SHARP router models have a hidden debug function enabled that allows remote unauthenticated attackers to execute arbitrary OS commands with r...
Dec 23, 2024This vulnerability involves hard-coded credentials for the CyberPower PowerPanel test server present in production code. Attackers could use these cre...
May 15, 2024This CVE describes an authentication bypass vulnerability in Yifan YF325 routers due to leftover debug code in the httpd service. Attackers can send s...
Oct 11, 2023This CVE allows attackers to bypass Secure Boot restrictions by accessing the UEFI Shell in Ubuntu systems with vulnerable edk2 firmware. This could e...
Nov 26, 2025Active debug code vulnerability in RoamWiFi R10 devices allows network-adjacent unauthenticated attackers to perform unauthorized operations. This aff...
Apr 24, 2024CVE-2022-25995 is a command execution vulnerability in the console inhand functionality of InHand Networks InRouter302 devices. Attackers can send spe...
May 12, 2022This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Naver Comic Viewer. Attackers can explo...
May 28, 2021This vulnerability in Cisco RCM for Cisco StarOS Software allows unauthenticated remote attackers to execute arbitrary commands with root privileges b...
Nov 15, 2024Smart Video Doorbell devices with firmware versions before 2.01.078 contain active debug code that enables Telnet access. Attackers can connect via Te...
Nov 26, 2025This CVE involves active debug code in Intel UEFI reference platforms that could allow a privileged attacker to escalate privileges and cause denial o...
Nov 11, 2025This vulnerability in Ghostscript with Tesseract OCR allows attackers to read arbitrary files and write error messages to arbitrary locations via dire...
Jul 3, 2024This vulnerability allows remote unauthenticated attackers to bypass authentication on Mitsubishi Electric industrial robot controllers via unauthoriz...
Feb 2, 2023This vulnerability allows attackers with access to the UniFi Talk management network to invoke internal debug operations through the device API due to...
Oct 31, 2025This vulnerability allows attackers with cryptographic material to gain root access to B. Braun medical devices due to active debug code left in produ...
Apr 14, 2022This critical vulnerability in Netis WF-2404 routers allows attackers with physical access to activate test or debug logic via the UART interface, pot...
Mar 28, 2025This vulnerability affects multiple Siemens SIPROTEC 5 protection relay devices. It allows unauthenticated attackers with physical access to execute a...
Feb 11, 2025This Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal allows unauthenticated attackers to inject malicious scripts that exe...
Dec 9, 2025An active debug code vulnerability in Fortinet FortiClient for Windows allows local attackers to step through the application execution and retrieve s...
Nov 18, 2025This vulnerability allows unauthorized access to sensitive information when logs are captured, as eSE debug messages containing potentially sensitive ...
Aug 6, 2025An active debug code vulnerability in Mesh Wi-Fi router RP562B firmware allows network-adjacent authenticated attackers to access or modify device set...
Nov 12, 2024A vulnerability in serial device servers allows attackers with physical access to connect to the UART interface and gain unauthorized access to intern...
Dec 31, 2025About CWE-489 (CWE-489)
Our database tracks 23 CVEs classified as CWE-489, with 5 rated critical and 11 rated high severity. The average CVSS score for CWE-489 vulnerabilities is 7.9.
External reference: View CWE-489 on MITRE CWE →
Monitor CWE-489 Vulnerabilities
Get alerted when new CWE-489 CVEs affect your infrastructure.
Start Monitoring Free