CVE-2025-48396

8.3

Eaton · Brightlayer Software Suite (BLSS)

Eaton Brightlayer Software Suite contains an unrestricted file upload vulnerability that allows an authenticated attacker to achieve arbitrary code execution.

Executive summary

A critical vulnerability in Eaton Brightlayer Software Suite allows authenticated attackers to execute arbitrary code due to improper file upload validation.

Vulnerability

The software fails to properly validate file types during upload processes (CWE-434), which can be leveraged by an authenticated user to achieve remote code execution on the underlying system.

Business impact

Successful exploitation of this flaw grants an attacker the ability to execute arbitrary commands, potentially leading to full system compromise, data exfiltration, or lateral movement within the network. With a CVSS score of 8.3, this high-severity vulnerability poses a significant risk to operational integrity and should be addressed as a priority to prevent unauthorized control over critical infrastructure management software.

Remediation

Immediate Action: Update Eaton Brightlayer Software Suite to version 7.3.0.SCP004 or later to apply the necessary security patches.

Proactive Monitoring: Monitor server logs for suspicious file upload activity, particularly requests involving unexpected file extensions or deviations from standard administrative behavior.

Compensating Controls: Restrict access to the file upload functionality to trusted users only and employ a Web Application Firewall to filter traffic for malicious file upload patterns.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant security risk to the affected environment. Administrators must prioritize the deployment of the 7.3.0.SCP004 patch across all instances of the Brightlayer Software Suite immediately to mitigate the risk of unauthorized system access and exploitation.

More Eaton CVEs

Sources

Originally found and disclosed by Lang Khuong Duy (JuyLang) - Viettel IDC, per the CVE Program record.