Falhas do tipo CWE-489

94 resultados

Código de debug deixado em produção

É quando código temporário de desenvolvimento (prints, logs detalhados, flags de debug, endpoints secretos) permanece ativo na aplicação em produção. Isso expõe informações sensíveis, permite bypass de controles de segurança e facilita ataques porque o atacante consegue enxergar o funcionamento interno da aplicação.

Exemplo

Um desenvolvedor deixa um print() mostrando a senha do banco de dados, ou uma flag de debug que desativa validação de login, ou um endpoint não documentado que retorna dados administrativos. Quando o código vai para produção, qualquer pessoa com acesso consegue explorar isso.

Como mitigar

Remova todo código de debug antes do build em produção (use variáveis de ambiente ou compilação condicional). Implemente revisão de código e testes automatizados que verifiquem a ausência de flags de debug. Use ferramentas de análise estática para detectar pontos suspeitos deixados para trás.

CVE-2025-64983HIGHSmart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attacker to connect via TEPSS 0.3%CVE-2021-1391MEDIUMCisco IOS and IOS XE Software Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-45728HIGHAlgernon: Single-file mode unconditionally enables debug modeEPSS 0.3%CVE-2025-4106HIGHWatchGuard Firebox leftover debug code vulnerabilityEPSS 0.3%CVE-2024-30219MEDIUMActive debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug funEPSS 0.3%CVE-2020-8320MEDIUMAn internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.EPSS 0.3%CVE-2025-15017HIGHA vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical accEPSS 0.3%CVE-2026-66405HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.EPSS 0.3%CVE-2024-7756MEDIUMA potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges bEPSS 0.3%CVE-2021-1381MEDIUMCisco IOS XE Software Active Debug Code VulnerabilityEPSS 0.3%CVE-2024-41999MEDIUMSmart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an atEPSS 0.3%CVE-2025-42872MEDIUMCross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise PortalEPSS 0.3%CVE-2026-66403HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affeEPSS 0.3%CVE-2026-27131MEDIUMSprig Plugin for Craft CMS potentially discloses sensitive information via Sprig PlaygroundEPSS 0.3%CVE-2026-66787MEDIUMLighthouse: go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082EPSS 0.2%CVE-2026-65893HIGHArbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP CameraEPSS 0.2%CVE-2025-52663HIGHA vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This iEPSS 0.2%CVE-2026-77545CRITICALA malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability fEPSS 0.2%CVE-2024-29075MEDIUMActive debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, EPSS 0.2%CVE-2025-7705HIGHAuthentication bypass due to compatibility mode enabled by defaultEPSS 0.2%