CVE-2024-32053
published 2024-05-15CVE-2024-32053: Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.47%
37.4th percentile
Hard-coded credentials are used by the
CyberPower PowerPanel
platform to authenticate to the
database, other services, and the cloud. This could result in an
attacker gaining access to services with the privileges of a Powerpanel
business application.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cyberpower | powerpanel | <= 4.9.0 | — |
| cyberpower | powerpanel_business | < 4.9.0 | 4.9.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
CyberPower PowerPanel business
cisa_ics·2025-08-12·CVSS 9.8
[CRITICAL] CyberPower PowerPanel business
ICS Advisory
##
CyberPower PowerPanel business
Last RevisedAugust 12, 2025
Alert CodeICSA-24-123-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: CyberPower
- Equipment: PowerPanel Business
- Vulnerabilities: Use of Hard-coded Password, Relative Path Traversal, Use of Hard-coded Credentials, Active Debug Code, Storing Passwords in a Recoverable Format, Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Use of Hard-coded Cryptographic Key, Incorrect Authorization
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in an attacker bypassin
OSV
libsoup2.4 vulnerabilities
osv·2025-06-11·CVSS 6.5
CVE-2024-52531 libsoup2.4 vulnerabilities
libsoup2.4 vulnerabilities
It was discovered that libsoup did not correctly handle memory while
performing UTF-8 conversions. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 16.04 LTS. (CVE-2024-52531)
It was discovered that libsoup could enter an infinite loop when reading
certain websocket data. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2024-52532)
It was discovered that libsoup could be made to read out of bounds. An
attacker could possibly use this issue to cause applications using
libsoup to crash, resulting in a denial of service. (CVE-2025-2784,
CVE-2025-32050, CVE-2025-32052, CVE-2025-32053)
GHSA
GHSA-3m49-xc8r-9rm5: Hard-coded credentials are used by the
CyberPower PowerPanel
platform to authenticate to the
database, other services, and the cloud
ghsa_unreviewed·2024-05-15
CVE-2024-32053 [CRITICAL] CWE-798 GHSA-3m49-xc8r-9rm5: Hard-coded credentials are used by the
CyberPower PowerPanel
platform to authenticate to the
database, other services, and the cloud
Hard-coded credentials are used by the
CyberPower PowerPanel
platform to authenticate to the
database, other services, and the cloud. This could result in an
attacker gaining access to services with the privileges of a Powerpanel
business application.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloadshttps://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads
2024-05-15
Published