CWE-1191: On-Chip Debug and Test Interface With Improper Access Control
The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.
18 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-48970 — Life2000 Ventilator microcontroller lacks memory protection
- CVE-2025-52533 — Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and
- CVE-2025-9709 — NRF52810 Runtime EM Fault Injection APPROTECT Bypass
- CVE-2024-41692 — Incorrect Access Control Vulnerability
- CVE-2026-15203 — Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software
- CVE-2026-8989 — Open Recovery Mode
- CVE-2026-8988 — Access to Bootloader
- CVE-2024-4231 — Incorrect Access Control Vulnerability in Digisol Router
- CVE-2025-7213 — FNKvision FNK-GU2 UART Interface on-chip debug and test interface with improper access control
- CVE-2025-47822 — Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper
- CVE-2025-47819 — Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.
- CVE-2024-36319 — Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously cr
- CVE-2025-12114 — Serial Console Enabled
- CVE-2025-36755 — CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard
- CVE-2025-15083 — TOZED ZLT M30s UART on-chip debug and test interface with improper access control
- CVE-2025-26409 — Access to Bootloader and Shell Over Serial Interface
- CVE-2025-26408 — Unprotected JTAG Interface
Recently published
- CVE-2026-15203 — Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software
- CVE-2026-8989 — Open Recovery Mode
- CVE-2026-8988 — Access to Bootloader
- CVE-2024-36319 — Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously cr
- CVE-2025-52533 — Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and
- CVE-2025-15083 — TOZED ZLT M30s UART on-chip debug and test interface with improper access control
- CVE-2025-36755 — CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard
- CVE-2025-12114 — Serial Console Enabled
- CVE-2025-9709 — NRF52810 Runtime EM Fault Injection APPROTECT Bypass
- CVE-2025-7213 — FNKvision FNK-GU2 UART Interface on-chip debug and test interface with improper access control
- CVE-2025-47822 — Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper
- CVE-2025-47819 — Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.
- CVE-2025-26409 — Access to Bootloader and Shell Over Serial Interface
- CVE-2025-26408 — Unprotected JTAG Interface
- CVE-2024-48970 — Life2000 Ventilator microcontroller lacks memory protection
- CVE-2024-41692 — Incorrect Access Control Vulnerability
- CVE-2024-4231 — Incorrect Access Control Vulnerability in Digisol Router