Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CyberPower — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting CyberPower. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CyberPower Systems manufactures uninterruptible power supplies (UPS) and power distribution units primarily for commercial and residential energy backup. The company’s network-connected management software and firmware have historically exposed devices to significant security risks, resulting in twenty recorded Common Vulnerabilities and Exposures. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from inadequate input validation and weak authentication mechanisms in web interfaces. While no widespread public breaches have been widely reported, the presence of these vulnerabilities allows attackers to potentially gain unauthorized control over power management systems, disrupting critical infrastructure operations. The recurring nature of these issues highlights persistent challenges in securing embedded IoT devices with limited patching cycles. Users are advised to isolate these devices on segmented networks and regularly update firmware to mitigate exploitation risks associated with the identified software defects.

CVE ID Title CVSS Severity Published
CVE-2024-31409 CyberPower PowerPanel business Incorrect Authorization — PowerPanel business CWE-863 6.5 Medium 2024-05-15
CVE-2024-31410 CyberPower PowerPanel business Use of Hard-coded Cryptographic Key — PowerPanel business CWE-321 7.7 High 2024-05-15
CVE-2024-31856 CyberPower PowerPanel business SQL Injection — PowerPanel business CWE-89 8.8 High 2024-05-15
CVE-2024-32042 CyberPower PowerPanel business Storing Passwords in a Recoverable Format — PowerPanel business CWE-257 4.9 Medium 2024-05-15
CVE-2024-32047 CyberPower PowerPanel business Active Debug Code — PowerPanel business CWE-489 9.8 Critical 2024-05-15
CVE-2024-32053 CyberPower PowerPanel business Use of Hard-coded Credentials — PowerPanel business CWE-798 9.8 Critical 2024-05-15
CVE-2024-33615 CyberPower PowerPanel business Relative Path Traversal — PowerPanel business CWE-23 8.8 High 2024-05-15
CVE-2024-33625 CyberPower PowerPanel business Use of Hard-coded Password — PowerPanel business CWE-259 9.8 Critical 2024-05-15
CVE-2024-34025 CyberPower PowerPanel business Use of Hard-coded Password — PowerPanel business CWE-259 9.8 Critical 2024-05-15
CVE-2024-32739 CyberPower PowerPanel Enterprise SQL Injection — CyberPower PowerPanel Enterprise 7.5 High 2024-05-09
CVE-2024-32738 CyberPower PowerPanel Enterprise SQL Injection — CyberPower PowerPanel Enterprise 7.5 High 2024-05-09
CVE-2024-32737 CyberPower PowerPanel Enterprise SQL Injection — CyberPower PowerPanel Enterprise 7.5 High 2024-05-09
CVE-2024-32736 CyberPower PowerPanel Enterprise SQL Injection — CyberPower PowerPanel Enterprise 7.5 High 2024-05-09
CVE-2024-32735 CyberPower PowerPanel Enterprise Missing Authentication — CyberPower PowerPanel Enterprise 9.8 Critical 2024-05-09
CVE-2023-3267 CyberPower PowerPanel Business Edition 操作系统命令注入漏洞 — PowerPanel Enterprise CWE-78 9.1 Critical 2023-08-14
CVE-2023-3266 CyberPower PowerPanel Business Edition 安全漏洞 — PowerPanel Enterprise CWE-358 9.8 Critical 2023-08-14
CVE-2023-3265 Cyber Power Systems CyberPower PowerPanel Enterprise 安全漏洞 — PowerPanel Enterprise CWE-150 9.8 Critical 2023-08-14
CVE-2023-25133 Improper privilege management vulnerability in CyberPower PowerPanel Business — PowerPanel Business Local / Remote CWE-269 9.1 Critical 2023-04-24
CVE-2023-25131 Use of default password vulnerability in CyberPower PowerPanel Business — PowerPanel Business Local / Remote CWE-1393 9.4 Critical 2023-04-24
CVE-2023-25132 Unrestricted upload of file with dangerous type vulnerability in CyberPower PowerPanel Business — PowerPanel Business Local / Remote CWE-434 9.1 Critical 2023-04-24

This page lists every published CVE security advisory associated with CyberPower. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.