Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system configuration, enumerate connected UPS devices and shut down connected UPS devices. This extends to being able to configure operating system commands that should run if the system detects a connected UPS shutting down.
                
            Metrics
Affected Vendors & Products
References
        History
                    Sat, 23 Aug 2025 11:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Voltronicpower Voltronicpower viewpower | |
| Vendors & Products | Voltronicpower Voltronicpower viewpower | 
Fri, 22 Aug 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-284 CWE-306 CWE-425 | |
| Metrics | cvssV3_1 
 
 | 
Fri, 22 Aug 2025 19:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system configuration, enumerate connected UPS devices and shut down connected UPS devices. This extends to being able to configure operating system commands that should run if the system detects a connected UPS shutting down. | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2025-08-22T00:00:00.000Z
Updated: 2025-08-22T20:25:23.662Z
Reserved: 2022-10-17T00:00:00.000Z
Link: CVE-2022-43110
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-08-22T20:24:52.427Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-08-22T20:15:31.777
Modified: 2025-08-25T20:24:45.327
Link: CVE-2022-43110
 Redhat
                        Redhat
                    No data.