Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the PubkeyAuthentication option.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HEaton Power Xpert Meter 4000
HWEatonall versionsEaton Power Xpert Meter 4000 Firmware
OSEaton< 13.4.0.10Eaton Power Xpert Meter 6000
HWEatonall versionsEaton Power Xpert Meter 6000 Firmware
OSEaton< 13.4.0.10Eaton Power Xpert Meter 8000
HWEatonall versionsEaton Power Xpert Meter 8000 Firmware
OSEaton< 13.4.0.10
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2021-23281CRITICAL10.0PL ✓same vendor
Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP
CVE-2018-8847CRITICAL9.8PL ✓same vendor
Stack-based buffer overflow w Eaton 9000X Drive umożliwiający RCE
CVE-2018-12031CRITICAL9.8PL ✓same vendor
Path Traversal (LFI) w Eaton Intelligent Power Manager v1.6
CVE-2026-22619HIGH7.8same vendor
Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could...
CVE-2025-59887HIGH8.6same vendor
Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary...