S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-33174 Scanner

Detects 'Authorization Bypass' vulnerability in Powertek firmware affects v. before 3.30.30.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-33174
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Power Distribution Units (PDUs) are important devices that aid power supply in data centers and server rooms. Powertek firmware is a popular software used by multiple PDU brands to run their devices. The firmware is responsible for managing power distribution, monitoring and controlling power usage in racks, and providing real-time data to administrators. Powertek firmware is favored by many companies because of its flexibility, scalability, and compatibility with different PDU brands.

However, a critical vulnerability, CVE-2022-33174, has been detected in Powertek firmware before version 3.30.30. The vulnerability allows remote authorization bypass in the web interface, and attackers can exploit it by sending an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie value set to an empty string followed by a semicolon. This allows the attacker to bypass the active session authorization check, thereby granting system access to unauthorized users.

When exploited, this vulnerability can give attackers full control over the PDU, allowing them to manipulate power usage in the PDU, disrupt power supply to connected devices, and access critical data stored in the PDU. Exposing devices to potential cyber-attacks could lead to costly damages, including loss of data, business disruption, and reputational damage.

s4e.io is a platform that offers comprehensive security solutions to businesses and individuals. Through its pro features, users can access valuable information about vulnerabilities in their digital assets, get insights about threats to their systems, and learn how to mitigate risks. By subscribing to the platform, users can stay up-to-date on the latest security trends and technologies, and keep their systems protected from emerging cyber threats. Protecting sensitive business data and systems from cyber-attacks is critical, and s4e.io offers the expertise and resources to achieve that.

 

REFERENCES

Solution Advice

The following precautions can be taken to protect against this vulnerability:

  • Install the latest Powertek firmware version, which addresses the vulnerability.
  • Monitor network traffic and look for unusual activities on network devices such as the PDU.
  • Limit the number of devices that can access the PDU's web interface.
  • Use strong authentication mechanisms to restrict remote access to the PDU, such as using two-factor authentication.
  • Disable unused network ports to reduce the PDU's attack surface.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.