The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for u
Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mo
A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug
Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB a
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to th
Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws
JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthentica
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path
When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log informatio
Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vul
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst
The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior
Development and test API endpoints are present that mirror production functionality.
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An atta
Frequently Asked Questions
What is CWE-489?
CWE-489 (CWE-489) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-489?
There are 17 CVE records associated with CWE-489 in our database. Of these, 3 are critical severity, 7 are high severity, and 6 are medium severity.
How can I protect against CWE-489 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-489 using AI-powered security agents.
Detect CWE-489 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-489 vulnerabilities across your infrastructure.
Get Started