GPU VulnDB

Database/Control plane, storage & DevOps

CyberPower PowerPanel business application - JWT signing key: The JWT signing key is hardcoded in the application, so

CVE-2024-33625Control plane, storage & DevOpscurated

Impact

The JWT signing key is hardcoded in the application, so an attacker forges any token they like and becomes any user. Same shape as the hardcoded credentials: a secret that is not secret and cannot be rotated by the operator.

Who can reach it

Unauthenticated, remote. Requires only the shipped software to extract the key.

What to do

Vendor upgrade. Nothing an operator can configure fixes a hardcoded signing key. Isolate the host until patched, and treat any PowerPanel instance that was internet-reachable as compromised.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.