← Vulnerability feed

Vulnerability record · CVE-2023-25131 · published 24 April 2023

CVE-2023-25131: Cyberpower powerpanel improper authentication vulnerability

Cyberpower · Powerpanel

Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 64bit v4.8.6 and earlier, PowerPanel Business Management for Linux 32bit v4.8.6 and earlier, PowerPanel Business Management for Linux 64bit v4.8.6 and earlier, PowerPanel Business Local/Remote for MacOS v4.8.6 and earlier, and PowerPanel Business Management for MacOS v4.8.6 and earlier allows remote attackers to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the 'admin' password.

9.8 CVSS 3.1 Critical EPSS 0.97% · top 39.7% CWE-1393 · CWE-1393CWE-287 · Improper authentication
9.8CVSS 3.1 base score
0.97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 64bit v4.8.6 and earlier, PowerPanel Business Management for Linux 32bit v4.8.6 and earlier, PowerPanel Business Management for Linux 64bit v4.8.6 and earlier, PowerPanel Business Local/Remote for MacOS v4.8.6 and earlier, and PowerPanel Business Management for MacOS v4.8.6 and earlier allows remote attackers to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the 'admin' password.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-25131 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-34025Cyberpower powerpanel hard-coded password vulnerabilityCyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing a…EPSS 0.56%9.8CVE-2024-32047Cyberpower powerpanel vulnerabilityHard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining access…EPSS 0.51%9.8CVE-2024-32053Cyberpower powerpanel hard-coded credentials vulnerabilityHard-coded credentials are used by the  CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could res…EPSS 0.47%9.8CVE-2024-33625Cyberpower powerpanel hard-coded password vulnerabilityCyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass …EPSS 0.52%9.8CVE-2024-32735Cyberpower powerpanel missing authentication for critical function vulnerabilityAn issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote…EPSS 6.8%9.8CVE-2023-25133Cyberpower powerpanel improper privilege management vulnerabilityImproper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Busine…EPSS 1.0%9.8CVE-2023-25132Cyberpower powerpanel unrestricted file upload vulnerabilityUnrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier,…EPSS 1.1%8.8CVE-2024-31856Cyberpower powerpanel sql injection vulnerabilityAn attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker inject…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2023-25131), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.