VYPR

Basic Pdu Firmware

by Powertekpdus

CVEs (2)

  • CVE-2022-33174CriJun 13, 2022
    risk 0.65cvss 9.8epss 0.14

    Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the…

  • CVE-2022-33175CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.02

    Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently…