Loading HuntDB...

cyberpower

7 Products 20 CVEs

CVE Severity Distribution (All Time)

Critical
11
High
7
Medium
2
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-31409 MEDIUM 1 year, 1 month ago

Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the sy…

CVE-2024-31410 HIGH 1 year, 1 month ago

The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to im…

CVE-2024-31856 HIGH 1 year, 1 month ago

An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker injec…

CVE-2024-32042 MEDIUM 1 year, 1 month ago

The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, allowing the passwords to be …

CVE-2024-32047 CRITICAL 1 year, 1 month ago

Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining acce…

CVE-2024-32053 CRITICAL 1 year, 1 month ago

Hard-coded credentials are used by the  CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could…

CVE-2024-33615 HIGH 1 year, 1 month ago

A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel server, which allows file writing …

CVE-2024-33625 CRITICAL 1 year, 1 month ago

CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypas…

CVE-2024-34025 CRITICAL 1 year, 1 month ago

CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing …

CVE-2024-32739 HIGH 1 year, 1 month ago

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive infor…