CVE-2022-43110

Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system configuration, enumerate connected UPS devices and shut down connected UPS devices. This extends to being able to configure operating system commands that should run if the system detects a connected UPS shutting down.
Configurations

No configuration.

History

25 Aug 2025, 20:24

Type Values Removed Values Added
Summary
  • (es) Voltronic Power ViewPower (versión 1.04-21353) y PowerShield Netguard (versión anterior a 1.04-23292) permiten a un atacante remoto configurar el sistema mediante una interfaz web no especificada. Un atacante remoto no autenticado puede realizar cambios en el sistema, como cambiar la contraseña de administrador de la interfaz web, ver/modificar la configuración del sistema, enumerar y apagar los dispositivos UPS conectados. Esto incluye la posibilidad de configurar los comandos del sistema operativo que deben ejecutarse si el sistema detecta que un UPS conectado se apaga.

22 Aug 2025, 21:15

Type Values Removed Values Added
CWE CWE-306
CWE-425
CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

22 Aug 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-22 20:15

Updated : 2025-08-25 20:24


NVD link : CVE-2022-43110

Mitre link : CVE-2022-43110

CVE.ORG link : CVE-2022-43110


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-306

Missing Authentication for Critical Function

CWE-425

Direct Request ('Forced Browsing')