CVE-2024-33625

9.8CRITICAL

CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.

Published: 5/15/2024Updated: 8/4/2025

Description

CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.

AI AnalysisPowered by AI

Affected Products

cyberpowerpowerpanel

References