← back
CVE-2022-33174critical

CVE-2022-33174

68Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 9.8epss 13%
from disclosure to weapon81 days
Published on NVDJun 13
1st PoC+81d
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.