Database/Control plane, storage & DevOps

CyberPower PowerPanel MQTT message handling: An attacker with MQTT publish permissions can craft messages
Impact
An attacker with MQTT publish permissions can craft messages to all managed PowerPanel devices, achieving SQL injection, arbitrary file write and remote code execution. Combined with the shared-certificate flaw, obtaining those permissions is not a high bar. One compromised device becomes code execution across the power-management estate.
Who can reach it
Anyone able to publish on the PowerPanel MQTT broker - reachable via the shared device certificate, or from any device already on the management network.
What to do
Vendor upgrade. Separately, put the MQTT broker on a segment reachable only by the devices that must use it, and monitor for publishers you do not recognise. MQTT wildcards should be blocked at the broker (see the companion issue CVE-2024-31409).
References
Related entries
- AMD Graphics Driver - crafted pointer leading to arbitrary code execution: Improper input validation in the AMDCVE-2024-36324 · AMD Graphics Driver - crafted pointer leading to arbitrary code executionHigh
- Jenkins: Agent processes can read arbitrary controller files via ClassLoaderProxy#fetchJarCVE-2024-43044 · JenkinsHigh
- Digi ConnectPort LTS (before 1.4.12): An attacker who can reach the ConnectPort LTS's file-upload featureCVE-2024-50627 · Digi ConnectPort LTS (before 1.4.12)High
- Deep Sea Electronics DSE855 generator communications gateway: Six unauthenticated flaws in one device: two stack-basedCVE-2024-5948 · Deep Sea Electronics DSE855 generator communications gatewayHigh
- PostgreSQL: TOCTOU race in pg_dumpCVE-2024-7348 · PostgreSQLHigh
- Automated Logic / Carrier i-Vu Gen5 BACnet router (drv_gen5_106-01-2380) and i-Vu Zone Controller: Malformed BACnetCVE-2025-0657 · Automated Logic / Carrier i-Vu Gen5 BACnet router (drv_gen5_106-01-2380) and i-Vu Zone ControllerHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.