Product
cyberpower powerpanel
18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-34025
CVE-2024-33625
CVE-2024-32053
CVE-2024-32047
CVE-2024-32042
CVE-2024-31856
CVE-2024-31410
CVE-2024-31409
CVE-2024-32739
CVE-2024-32738
CVE-2024-32737
CVE-2024-32736
CVE-2024-32735
CVE-2023-25133
CVE-2023-25132
CVE-2023-25131
CVE-2019-13071
CVE-2019-13070
<= 4.9.0
CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an
<= 4.9.0
CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging
<= 4.9.0
Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other services, and t
<= 4.9.0
Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an at
<= 4.9.0
The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, allowing t
<= 4.9.0
An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result i
<= 4.9.0
The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. This can allo
<= 4.9.0
Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data fro
< 2.8.3
A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can
< 2.8.3
A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can
< 2.8.3
A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can
< 2.8.3
A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can
< 2.8.3
An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An un
<= 4.8.6
Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier
<= 4.8.6
Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows
<= 4.8.6
Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Mana
all versions
CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to a
all versions
A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privileged attac