CWE-489: CWE-489

23
Total CVEs
5
Critical
11
High
7.9
Avg CVSS

Yearly Trend

2025
11
2024
6
2023
3
2022
2
2021
1

Top Affected Vendors

1 Fortinet 1
2 Qualcomm 1
3 Naver 1
4 Tianocore 1
5 Four Faith 1
6 Artifex 1
7 Netis Systems 1
8 Mitsubishielectric 1
9 Johnsoncontrols 1
10 Cyberpower 1

All CWE-489 CVEs (23)

CVE-2023-4804
10.0

Unauthorized users can access debug features in Quantum HD Unity products that were accidentally exposed. This affects all Quantum HD Unity products w...

Nov 10, 2023
CVE-2024-9643
9.8

The Four-Faith F3x36 router firmware v2.0.0 contains hard-coded administrative credentials, allowing attackers to bypass authentication and gain full ...

Feb 4, 2025
CVE-2024-46873
9.8

Multiple SHARP router models have a hidden debug function enabled that allows remote unauthenticated attackers to execute arbitrary OS commands with r...

Dec 23, 2024
CVE-2024-32047
9.8

This vulnerability involves hard-coded credentials for the CyberPower PowerPanel test server present in production code. Attackers could use these cre...

May 15, 2024
CVE-2023-32645
9.8

This CVE describes an authentication bypass vulnerability in Yifan YF325 routers due to leftover debug code in the httpd service. Attackers can send s...

Oct 11, 2023
CVE-2025-2486
8.8

This CVE allows attackers to bypass Secure Boot restrictions by accessing the UEFI Shell in Ubuntu systems with vulnerable edk2 firmware. This could e...

Nov 26, 2025
CVE-2024-31406
8.8

Active debug code vulnerability in RoamWiFi R10 devices allows network-adjacent unauthenticated attackers to perform unauthorized operations. This aff...

Apr 24, 2024
CVE-2022-25995
8.8

CVE-2022-25995 is a command execution vulnerability in the console inhand functionality of InHand Networks InRouter302 devices. Attackers can send spe...

May 12, 2022
CVE-2021-33591
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Naver Comic Viewer. Attackers can explo...

May 28, 2021
CVE-2022-20649
8.1

This vulnerability in Cisco RCM for Cisco StarOS Software allows unauthenticated remote attackers to execute arbitrary commands with root privileges b...

Nov 15, 2024
CVE-2025-64983
8.0

Smart Video Doorbell devices with firmware versions before 2.01.078 contain active debug code that enables Telnet access. Attackers can connect via Te...

Nov 26, 2025
CVE-2025-30185
7.9

This CVE involves active debug code in Intel UEFI reference platforms that could allow a privileged attacker to escalate privileges and cause denial o...

Nov 11, 2025
CVE-2024-29511
7.5

This vulnerability in Ghostscript with Tesseract OCR allows attackers to read arbitrary files and write error messages to arbitrary locations via dire...

Jul 3, 2024
CVE-2022-33323
7.5

This vulnerability allows remote unauthenticated attackers to bypass authentication on Mitsubishi Electric industrial robot controllers via unauthoriz...

Feb 2, 2023
CVE-2025-52663
7.3

This vulnerability allows attackers with access to the UniFi Talk management network to invoke internal debug operations through the device API due to...

Oct 31, 2025
CVE-2020-25156
7.2

This vulnerability allows attackers with cryptographic material to gain root access to B. Braun medical devices due to active debug code left in produ...

Apr 14, 2022
CVE-2025-2919
6.8

This critical vulnerability in Netis WF-2404 routers allows attackers with physical access to activate test or debug logic via the UART interface, pot...

Mar 28, 2025
CVE-2024-53648
6.8

This vulnerability affects multiple Siemens SIPROTEC 5 protection relay devices. It allows unauthenticated attackers with physical access to execute a...

Feb 11, 2025
CVE-2025-42872
6.1

This Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal allows unauthenticated attackers to inject malicious scripts that exe...

Dec 9, 2025
CVE-2025-54660
5.5

An active debug code vulnerability in Fortinet FortiClient for Windows allows local attackers to step through the application execution and retrieve s...

Nov 18, 2025
CVE-2025-21472
5.5

This vulnerability allows unauthorized access to sensitive information when logs are captured, as eSE debug messages containing potentially sensitive ...

Aug 6, 2025
CVE-2024-29075
4.6

An active debug code vulnerability in Mesh Wi-Fi router RP562B firmware allows network-adjacent authenticated attackers to access or modify device set...

Nov 12, 2024
CVE-2025-15017
N/A

A vulnerability in serial device servers allows attackers with physical access to connect to the UART interface and gain unauthorized access to intern...

Dec 31, 2025

About CWE-489 (CWE-489)

Our database tracks 23 CVEs classified as CWE-489, with 5 rated critical and 11 rated high severity. The average CVSS score for CWE-489 vulnerabilities is 7.9.

External reference: View CWE-489 on MITRE CWE →

Monitor CWE-489 Vulnerabilities

Get alerted when new CWE-489 CVEs affect your infrastructure.

Start Monitoring Free