An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker injecting SQL syntax, writing arbitrary files to the system, and executing remote code.
History

Wed, 30 Jul 2025 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Cyberpower powerpanel
CPEs cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:business:windows:*:*
Vendors & Products Cyberpower powerpanel

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-05-15T19:52:37.407Z

Updated: 2024-08-02T01:59:49.843Z

Reserved: 2024-04-29T16:47:22.333Z

Link: CVE-2024-31856

cve-icon Vulnrichment

Updated: 2024-05-16T18:09:22.415Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-15T20:15:11.710

Modified: 2025-07-30T00:20:33.280

Link: CVE-2024-31856

cve-icon Redhat

No data.