← Vulnerability feed

Vulnerability record · CVE-2022-33175 · published 13 June 2022

CVE-2022-33175: Powertekpdus basic pdu firmware incorrect permission assignment vulnerability

Powertekpdus · Basic Pdu Firmware

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently logged-in administrators. The session id can then be reused to act as the administrator, allowing reading of the cleartext password, or reconfiguring the device.

9.8 CVSS 3.1 Critical EPSS 1.7% · top 23.6% CWE-732 · Incorrect permission assignment
9.8CVSS 3.1 base score, v2 7.5
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently logged-in administrators. The session id can then be reused to act as the administrator, allowing reading of the cleartext password, or reconfiguring the device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://gynvael.coldwind.pl/?lang=en&id=748 ExploitThird Party Advisory
https://gynvael.coldwind.pl/?lang=en&id=748 ExploitThird Party Advisory

Track CVE-2022-33175 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2022-33175), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.