CVE-2025-8284

CRITICAL

Packet Power EMX and EG - Unauthenticated Access to Monitoring and Control Functions

Title source: llm
STIX 2.1

Description

By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulnerability could allow unauthorized users to access and manipulate monitoring and control functions.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-25-219-05

Scores

CVSS v3 9.8
EPSS 0.0051
EPSS Percentile 39.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (2)
Packet Power/EG < 4.1.0
Packet Power/EMX < 4.1.0
Published Aug 08, 2025
Tracked Since Feb 18, 2026