CVE-2023-3265
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator with hardcoded default credentials.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.19%
- CWE
- CWE-150
- Published
- 2023-08-14
- Last modified
- 2026-03-13
Affected products
- CyberPower PowerPanel Enterprise
Weakness type
Related vulnerabilities
- CVE-2025-55754 — Apache Tomcat: console manipulation via escape sequences in log messages
- CVE-2020-6932 — An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Softwa
- CVE-2023-26055 — XWiki Commons may allow privilege escalation to programming rights via user's first name
- CVE-2025-25286 — Crayfish allows Remote Code Execution via Homarus Authorization header
- CVE-2025-47284 — Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation
- CVE-2024-32986 — Arbitrary code execution due to improper sanitization of web app properties in PWAsForFirefox
- CVE-2023-28446 — Deno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralization
- CVE-2025-0975 — IBM MQ code execution