Vulnerabilities & Exploits

UPS Cards Become a Power-Control Risk

The weak point is the UPS management card, not the rack hardware. If an attacker gets into that admin plane, the card can become a control point for power continuity, which means a clean shutdown or stable uptime is no longer guaranteed.

Claroty’s Team82 found two critical flaws in Vertiv Liebert IS-UNITY-DP and RDU101 cards: an authentication bypass on the web interface and a stack-based buffer overflow that can lead to remote code execution. Vertiv says firmware is available in 1.9.1.2_0000001 for Liebert RDU101 and 8.4.3.1_00160 for IS-UNITY devices.

The operational risk is wider than a normal appliance bug. These cards sit in the path that keeps dependent systems online or shuts them down safely, so compromise can create a direct outage trigger across data center and critical infrastructure environments.

2 sources · Jun 11

CVE-2025-41426

NVD KEV

CVSS 9.8 CRITICAL: affected Vertiv products contain a stack based buffer overflow vulnerability. EPSS 0.8% (52nd percentile).

CVE-2025-46412

NVD KEV

CVSS 9.8 CRITICAL: affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass… EPSS 0.6% (45th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-06-11

Every edition of this story: UPS Cards Become a Power-Control Risk

More from today