Weaknesses of type CWE-489

93 results

Código de depuração deixado em produção

Código temporário de debug — logs verbosos, print statements, rotas de teste, funcionalidades desativadas com comentários — permanece na aplicação em produção. Isso expõe informações sensíveis (stack traces, caminhos internos, tokens) e pode criar portas traseiras acidentais que atacantes exploram para contornar autenticação ou acessar recursos restritos.

Example

Um desenvolvedor deixa um endpoint `/admin/test` acessível sem autenticação para testar fluxos, ou uma função de debug que imprime credenciais no log de erros. Um atacante descobre e usa isso para ganhar acesso administrativo ou extrair secrets.

How to mitigate

Remova todo código de debug antes do merge para produção (code review obrigatório), use variáveis de ambiente para controlar níveis de log (nunca verbose em prod), e automatize a detecção com linters que flagrem console.log, print() ou rotas de teste conhecidas. Mantenha debug apenas em branches isolados ou ambientes de staging.

CVE-2025-64983HIGHSmart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attacker to connect via TEPSS 0.3%CVE-2021-1391MEDIUMCisco IOS and IOS XE Software Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-45728HIGHAlgernon: Single-file mode unconditionally enables debug modeEPSS 0.3%CVE-2025-4106HIGHWatchGuard Firebox leftover debug code vulnerabilityEPSS 0.3%CVE-2024-30219MEDIUMActive debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug funEPSS 0.3%CVE-2020-8320MEDIUMAn internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.EPSS 0.3%CVE-2025-15017HIGHA vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical accEPSS 0.3%CVE-2026-66405HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.EPSS 0.3%CVE-2024-7756MEDIUMA potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges bEPSS 0.3%CVE-2021-1381MEDIUMCisco IOS XE Software Active Debug Code VulnerabilityEPSS 0.3%CVE-2024-41999MEDIUMSmart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an atEPSS 0.3%CVE-2025-42872MEDIUMCross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise PortalEPSS 0.3%CVE-2026-66403HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affeEPSS 0.3%CVE-2026-27131MEDIUMSprig Plugin for Craft CMS potentially discloses sensitive information via Sprig PlaygroundEPSS 0.3%CVE-2026-66787MEDIUMLighthouse: go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082EPSS 0.2%CVE-2026-65893HIGHArbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP CameraEPSS 0.2%CVE-2025-52663HIGHA vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This iEPSS 0.2%CVE-2026-77545CRITICALA malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability fEPSS 0.2%CVE-2024-29075MEDIUMActive debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, EPSS 0.2%CVE-2025-7705HIGHAuthentication bypass due to compatibility mode enabled by defaultEPSS 0.2%