Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system configuration, enumerate connected UPS devices and shut down connected UPS devices. This extends to being able to configure operating system commands that should run if the system detects a connected UPS shutting down.
Metrics
Affected Vendors & Products
References
History
Sat, 23 Aug 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Voltronicpower
Voltronicpower viewpower |
|
| Vendors & Products |
Voltronicpower
Voltronicpower viewpower |
Fri, 22 Aug 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-306 CWE-425 |
|
| Metrics |
cvssV3_1
|
Fri, 22 Aug 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system configuration, enumerate connected UPS devices and shut down connected UPS devices. This extends to being able to configure operating system commands that should run if the system detects a connected UPS shutting down. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-08-22T00:00:00.000Z
Updated: 2025-08-22T20:25:23.662Z
Reserved: 2022-10-17T00:00:00.000Z
Link: CVE-2022-43110
Updated: 2025-08-22T20:24:52.427Z
Status : Awaiting Analysis
Published: 2025-08-22T20:15:31.777
Modified: 2025-08-25T20:24:45.327
Link: CVE-2022-43110
No data.