← Vulnerability feed

Vulnerability record · CVE-2024-32735 · published 14 May 2024

CVE-2024-32735: Cyberpower powerpanel missing authentication for critical function vulnerability

Cyberpower · Powerpanel

An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.

9.8 CVSS 3.1 Critical EPSS 6.8% · top 6.2% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score
6.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-32735 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-34025Cyberpower powerpanel hard-coded password vulnerabilityCyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing a…EPSS 0.56%9.8CVE-2024-32047Cyberpower powerpanel vulnerabilityHard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining access…EPSS 0.51%9.8CVE-2024-32053Cyberpower powerpanel hard-coded credentials vulnerabilityHard-coded credentials are used by the  CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could res…EPSS 0.47%9.8CVE-2024-33625Cyberpower powerpanel hard-coded password vulnerabilityCyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass …EPSS 0.52%9.8CVE-2023-25133Cyberpower powerpanel improper privilege management vulnerabilityImproper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Busine…EPSS 1.0%9.8CVE-2023-25131Cyberpower powerpanel improper authentication vulnerabilityUse of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows …EPSS 0.97%9.8CVE-2023-25132Cyberpower powerpanel unrestricted file upload vulnerabilityUnrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier,…EPSS 1.1%8.8CVE-2024-31856Cyberpower powerpanel sql injection vulnerabilityAn attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker inject…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2024-32735), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.