Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Improper Input Validation in Eaton Tripp Lite PADM Firmware

Fri, 31 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Improper Input Validation in Eaton Tripp Lite PADM Firmware

Fri, 31 Jul 2026 10:30:00 +0000


Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Eaton
Eaton padm
Vendors & Products Eaton
Eaton padm

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Description Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Eaton

Published:

Updated: 2026-07-31T09:55:01.109Z

Reserved: 2026-01-08T04:55:11.730Z

Link: CVE-2026-22620

cve-icon Vulnrichment

Updated: 2026-07-30T12:24:25.999Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-30T11:16:27.130

Modified: 2026-07-31T11:17:08.000

Link: CVE-2026-22620

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:00:10Z

Weaknesses