PT-2026-32672 · Apc · Powerchute Serial Shutdown

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2026-2400

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PowerChute Serial Shutdown (affected versions not specified)
Description Improper neutralization of CRLF sequences, also known as CRLF Injection, occurs when the application fails to properly filter carriage return and line feed characters. This issue can be triggered when a Web Admin user modifies the payload of the 'POST /setPCBEDesc' request, potentially leading to the reset of application user credentials or a denial of service condition via specially crafted POST requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2026-05385
CVE-2026-2400

Affected Products

Powerchute Serial Shutdown