The product is released with debugging code still enabled or active.
Volume of CVEs assigned to CWE-489 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
84 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32645CRITICAL A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication | Oct 11, 2023 | 9.8 | 60 | NO | NO |
CVE-2017-5259HIGH In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or | Dec 20, 2017 | 8.8 | 59 | NO | YES |
CVE-2024-9643CRITICAL The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge | Feb 4, 2025 | 9.8 | 43 | NO | YES |
CVE-2026-49188CRITICAL The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands. | Jun 4, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-58378HIGH Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim al | Jul 9, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-59092HIGH JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics e | Jul 2, 2026 | 7.7 | 34 | NO | NO |
CVE-2026-9133HIGH Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate valid | May 20, 2026 | 7.7 | 33 | NO | NO |
CVE-2026-40035CRITICAL Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a st | Apr 8, 2026 | 9.1 | 32 | NO | NO |
CVE-2022-20649HIGH A vulnerability in Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level | Nov 15, 2024 | 8.1 | 32 | NO | NO |
CVE-2022-32585CRITICAL A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An at | Jun 30, 2022 | 9.8 | 32 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.