CVE-2023-3265

CRITICAL

CyberPower PowerPanel Enterprise < 2.6.9 - Unauthenticated Authentication Bypass via Username Meta-Character Injection

Title source: llm
STIX 2.1

Description

An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator with hardcoded default credentials.

Scores

CVSS v3 9.8
EPSS 0.0151
EPSS Percentile 71.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-150
Status published
Products (1)
cyberpower/powerpanel_server < 2.6.9
Published Aug 14, 2023
Tracked Since Feb 18, 2026