A critical vulnerability, tracked as CVE-2025-66237, has been identified in Sunbird's DCIM dcTrack and Power IQ platforms. The flaw involves the use of default and hard-coded credentials, which could allow an attacker to gain administrative access to the database, escalate privileges, or execute system commands on the host. The vulnerability affects DCIM dcTrack and Power IQ versions 9.2.0 and prior, and has been assigned a CVSS v4 base score of 8.4, indicating high severity.
According to CISA, successful exploitation of this vulnerability could enable unauthorized access or credential theft. The advisory highlights that an attacker leveraging these hard-coded credentials could compromise the integrity and security of the affected systems, potentially leading to broader network exposure. Organizations using impacted Sunbird products are urged to review mitigation guidance and update their systems to address this critical security risk.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2025-12-04, CVE-2025-66237 was published as a high-severity use of hard-coded credentials vulnerability in Sunbird DCIM dcTrack and Power IQ. The entry listed CISA ICS-CERT as the source, assigned a CVSS v4 score of 8.4, and recommended changing default credentials, rotating hard-coded credentials, and enforcing a secure password policy.
In the advisory published on 2025-12-04, Sunbird recommended upgrading dcTrack to version 9.2.3 and Power IQ to version 9.2.1 to address the disclosed vulnerabilities. CISA also said no known public exploitation specifically targeting these flaws had been reported at the time of publication.
On 2025-12-04, CISA published an ICS advisory for Sunbird DCIM dcTrack and Power IQ affecting version 9.2.0 and earlier. The advisory described CVE-2025-66238 and CVE-2025-66237 as remotely exploitable, low-complexity flaws that could enable unauthorized access, credential theft, privilege escalation, command execution, and access to restricted services or data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.