HIGH🇵🇱 Wersja polska

CVE-2025-67450

CVSS 7.8v3.1pub. 2025-12-26upd. 2026-02-18

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Eaton Ups Companion

    APP
    Eaton
    < 3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-59887HIGH8.6same product

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary...

CVE-2020-6650HIGH8.3same product

UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neut...

CVE-2025-59888MEDIUM6.7same product

Nieprawidłowe cytowanie w ścieżkach wyszukiwania w instalatorze oprogramowania Eaton UPS Companion może prowad...

CVE-2021-23281CRITICAL10.0PL ✓same vendor

Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP

CVE-2018-16158CRITICAL9.8PL ✓same vendor

Eaton Power Xpert Meter — zakodowany klucz SSH umożliwia logowanie jako root