GPU VulnDB

Database/Control plane, storage & DevOps

CyberPower PowerPanel MQTT message handling: An attacker with MQTT publish permissions can craft messages

CVE-2024-31856Control plane, storage & DevOpscurated

Impact

An attacker with MQTT publish permissions can craft messages to all managed PowerPanel devices, achieving SQL injection, arbitrary file write and remote code execution. Combined with the shared-certificate flaw, obtaining those permissions is not a high bar. One compromised device becomes code execution across the power-management estate.

Who can reach it

Anyone able to publish on the PowerPanel MQTT broker - reachable via the shared device certificate, or from any device already on the management network.

What to do

Vendor upgrade. Separately, put the MQTT broker on a segment reachable only by the devices that must use it, and monitor for publishers you do not recognise. MQTT wildcards should be blocked at the broker (see the companion issue CVE-2024-31409).

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.