Executive brief
A security vulnerability exists in the management software for Eaton Tripp Lite power distribution and backup devices. An authorized user with low-level access could exploit this flaw to gain full administrative control over the device. This could allow an attacker to disrupt power operations, modify critical settings, or use the device as a foothold within the corporate network.
Technical details
An OS command injection vulnerability (CWE-78) exists in the session management interface of Eaton Tripp Lite PADM firmware. The flaw stems from improper input validation of parameters passed through the web-based management interface. A remote attacker with low-privileged credentials can exploit this by sending specially crafted requests to execute arbitrary commands on the underlying operating system. Successful exploitation results in a complete compromise of the device with unrestricted administrative access. The vulnerability affects PADM versions up to and including version 20.
Affected products
- Eaton Tripp Lite series PADM firmware Versions 20 and prior
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory