Cyberpower develops a focused line of power-management and uninterruptible power supply (UPS) control software, with vulnerabilities concentrating in its PowerPanel remote monitoring and management platform. The vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the internet-facing nature of administrative interfaces and the high value of remote infrastructure access. The recurring weakness classes—SQL injection, OS command injection, hard-coded credentials, and input-validation gaps—indicate systemic input-handling and authentication deficiencies in software designed for privileged administrative access. Defenders should treat Cyberpower advisories as high-priority for any exposed management instances and inventory affected UPS and facility-control deployments; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cyberpower over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-32735CRITICAL An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU R | May 14, 2024 | 9.8 | 43 | NO | YES |
CVE-2024-32736HIGH A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_ver | May 14, 2024 | 7.5 | 37 | NO | YES |
CVE-2024-32739HIGH A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_ver | May 14, 2024 | 7.5 | 35 | NO | YES |
CVE-2024-32738HIGH A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_lea | May 14, 2024 | 7.5 | 35 | NO | YES |
CVE-2024-32737HIGH A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_ | May 14, 2024 | 7.5 | 35 | NO | YES |
CVE-2024-32053CRITICAL Hard-coded credentials are used by the
CyberPower PowerPanel
platform to authenticate to the
database, other services, and the cloud. This could result in an
attacker gaining | May 15, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-3266CRITICAL A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP authentication is selected.An | Aug 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-3265CRITICAL An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application wit | Aug 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-3264CRITICAL The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent wi | Aug 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-3267HIGH When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running | Aug 14, 2023 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cyberpower.
Media articles that mention a CVE ID that affects a product developed by Cyberpower — matched by CVE ID, not by vendor name.