GPU VulnDB

Database/Control plane, storage & DevOps

CyberPower PowerPanel business application - hardcoded authentication credentials: A hardcoded credential set compiled

CVE-2024-34025Control plane, storage & DevOpscurated

Impact

A hardcoded credential set compiled into the application gives administrator access to anyone who reads the binary. There is no configuration that removes it and no password rotation that helps. On a platform that controls power distribution, this is a permanent unauthenticated back door until the vendor ships a build without it.

Who can reach it

Unauthenticated, remote, using credentials extractable from the shipped software by anyone.

What to do

Upgrade to a build that removes the credentials - configuration changes cannot help. Until upgraded, the only real control is network isolation: the PowerPanel host must be unreachable from anything but a management jump box.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.