CVE-2024-31856

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
15/05/2024
Last modified:
30/07/2025

Description

An attacker with certain MQTT permissions can create malicious messages <br /> to all CyberPower PowerPanel devices. This could result in an attacker injecting <br /> SQL syntax, writing arbitrary files to the system, and executing remote <br /> code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:business:windows:*:* 4.9.0 (including)