Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.
History

Thu, 07 Aug 2025 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 07 Aug 2025 18:45:00 +0000

Type Values Removed Values Added
Title CyberPower PowerPanel business Improper Authorization CyberPower PowerPanel business Incorrect Authorization
Weaknesses CWE-863

Wed, 30 Jul 2025 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Cyberpower powerpanel
CPEs cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:business:windows:*:*
Vendors & Products Cyberpower powerpanel

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-05-15T20:00:22.532Z

Updated: 2025-08-07T18:26:54.578Z

Reserved: 2024-04-29T16:47:22.337Z

Link: CVE-2024-31409

cve-icon Vulnrichment

Updated: 2024-08-02T01:52:56.873Z

cve-icon NVD

Status : Modified

Published: 2024-05-15T20:15:11.203

Modified: 2025-08-07T19:15:28.180

Link: CVE-2024-31409

cve-icon Redhat

No data.