PT-2025-32183 · Eaton · Eaton

Harry Sintonen

·

Published

2025-08-06

·

Updated

2026-02-09

·

CVE-2025-48393

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Eaton (affected versions not specified)
Description The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented, potentially allowing an attacker to perform a Man-in-the-middle attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2025-48393

Affected Products

Eaton