HIGH🇵🇱 Wersja polska

CVE-2025-59887

CVSS 8.6v3.1pub. 2025-12-26upd. 2026-02-18

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Eaton Ups Companion

    APP
    Eaton
    < 3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-67450HIGH7.8same product

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the...

CVE-2020-6650HIGH8.3same product

UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neut...

CVE-2025-59888MEDIUM6.7same product

Nieprawidłowe cytowanie w ścieżkach wyszukiwania w instalatorze oprogramowania Eaton UPS Companion może prowad...

CVE-2021-23281CRITICAL10.0PL ✓same vendor

Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP

CVE-2018-16158CRITICAL9.8PL ✓same vendor

Eaton Power Xpert Meter — zakodowany klucz SSH umożliwia logowanie jako root