← Back to browse · API

CVE-2022-33175

Severity
CRITICAL
CVSS
9.8
EPSS
0.01733
Risk score
39.81
CISA KEV
No
PoC
No
Published
2022-06-13
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2022-36219, GHSA-X3X3-7Q8C-M397
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-36219

Description

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently logged-in administrators. The session id can then be reused to act as the administrator, allowing reading of the cleartext password, or reconfiguring the device.

References