logo

Attacking UPS Network Cards to Take Down Data Centers

ID: 5adbb267-3305-5989-afaa-8618611306fd

STIX ID: report--5adbb267-3305-5989-afaa-8618611306fd

Feed Name: Claroty Team82

Threat Score
85/100

Date Published: 2026-06-05

Date Updated: 2026-06-11

Author: Vera Mens

...
...

Team82 discovered two critical CVSS 9.8 vulnerabilities in Vertiv Liebert UPS network cards — an authentication-bypass URI confusion (CVE-2025-46412) and a stack-based buffer overflow leading to remote code execution (CVE-2025-41426). The report documents firmware analysis, exploitation techniques (config upload via crafted URL and ROP primitives from an overflow), successful validation on real hardware, and vendor-supplied firmware updates to mitigate the issues (RDU101 v1.9.1.2_0000001 and IS-UNITY v8.4.3.1_00160).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.