An attacker with certain MQTT permissions can create malicious messages
to all CyberPower PowerPanel devices. This could result in an attacker injecting
SQL syntax, writing arbitrary files to the system, and executing remote
code.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Jul 2025 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cyberpower powerpanel
|
|
CPEs | cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:business:windows:*:* | |
Vendors & Products |
Cyberpower powerpanel
|

Status: PUBLISHED
Assigner: icscert
Published: 2024-05-15T19:52:37.407Z
Updated: 2024-08-02T01:59:49.843Z
Reserved: 2024-04-29T16:47:22.333Z
Link: CVE-2024-31856

Updated: 2024-05-16T18:09:22.415Z

Status : Analyzed
Published: 2024-05-15T20:15:11.710
Modified: 2025-07-30T00:20:33.280
Link: CVE-2024-31856

No data.