Junglewise Threat Intelligence

CVE-2026-22620: Eaton Tripp Lite PADM authentication bypass via SQL injection

CVE-2026-22620 · Severity: high · CVSS 8.6 · Published 2026-07-30

Executive brief

A security vulnerability exists in the firmware used by Eaton's Tripp Lite series power management devices. An unauthorized person could remotely bypass the login screen to gain administrative control over the device. This could allow an attacker to disrupt power distribution, change critical settings, or cause a service outage.

Technical details

An authentication bypass vulnerability exists in the Eaton Tripp Lite series PADM firmware version 20 and earlier. The flaw is rooted in improper input validation within the authentication component, specifically identified as an SQL injection (CWE-89) vulnerability. A remote, unauthenticated attacker can exploit this by sending specially crafted network requests to the device's management interface. Successful exploitation allows the attacker to bypass security controls and gain privileged access, potentially leading to full device compromise or denial of service. Users are advised that this product series has reached End of Life (EOL).

Affected products

  • Eaton Tripp Lite series PADM firmware <= 20

Timeline

  • 2026-07-30: advisory: Initial disclosure by Eaton and NVD publication

References

Related threats