CVE-2022-43110

CRITICAL

Voltronic Power ViewPower <1.04-21353 & PowerShield Netguard <1.04-...

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-43110. PoCs published by ready2disclose.

AI-analyzed exploit summary The repository describes CVE-2022-43110, an authentication bypass vulnerability in Voltronic Viewpower/Pro UPS management software due to direct request forced browsing (CWE-425). It allows unauthenticated remote attackers to change configurations, enumerate devices, and execute OS commands.

Description

Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system configuration, enumerate connected UPS devices and shut down connected UPS devices. This extends to being able to configure operating system commands that should run if the system detects a connected UPS shutting down.

Exploits (1)

nomisec WRITEUP
by ready2disclose · poc
https://github.com/ready2disclose/CVE-2022-43110

The repository describes CVE-2022-43110, an authentication bypass vulnerability in Voltronic Viewpower/Pro UPS management software due to direct request forced browsing (CWE-425). It allows unauthenticated remote attackers to change configurations, enumerate devices, and execute OS commands.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target: Voltronic Viewpower/Pro and rebrands/derivatives
No auth needed
Prerequisites: Network access to the vulnerable UPS management interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-25-182-05

Scores

CVSS v3 9.8
EPSS 0.0062
EPSS Percentile 44.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-284 CWE-306 CWE-425
Status published
Published Aug 22, 2025
Tracked Since Feb 18, 2026