Unrated severityNVD Advisory· Published May 15, 2024· Updated Aug 2, 2024
CyberPower PowerPanel business SQL Injection
CVE-2024-31856
Description
An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker injecting SQL syntax, writing arbitrary files to the system, and executing remote code.
Affected products
2- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.