Junglewise Threat Intelligence

CVE-2026-22621: Eaton Tripp Lite Series PADM command injection in session management interface

CVE-2026-22621 · Severity: high · CVSS 8.3 · Published 2026-07-30

Executive brief

Eaton's Tripp Lite Series PADM firmware, which is used to manage power distribution units and uninterruptible power supplies, contains a security flaw in its session management interface. An authenticated administrator could exploit this weakness to run unauthorized commands on the device. This could lead to full control over the power management system, potentially resulting in unauthorized configuration changes or service disruptions.

Technical details

An OS command injection vulnerability (CWE-78) exists in the session management interface of Eaton Tripp Lite Series PADM firmware versions 20 and prior. The flaw stems from improper validation of input provided to the interface, which allows an authenticated user with administrator privileges to bypass restricted environments and execute arbitrary system commands. The attack vector is network-based and requires low complexity, though it does necessitate valid credentials. Successful exploitation grants the attacker high impact on confidentiality and integrity, and low impact on availability. Eaton has issued an End-of-Life (EOL) notice for the affected firmware version.

Affected products

  • Eaton Tripp Lite Series PADM firmware <= 20

Timeline

  • 2026-07-30: disclosed: Initial publication of the CVE record and Eaton advisory.

References