CVE-2026-22620

Eaton · PADM

Improper input validation in the authentication component of Eaton Tripp Lite series PADM firmware allows unauthenticated remote attackers to bypass authentication and gain privileged access.

Executive summary

An unauthenticated authentication bypass vulnerability in Eaton PADM firmware enables attackers to gain administrative control over the device, presenting a severe security risk.

Vulnerability

The vulnerability stems from improper input validation, identified as SQL injection (CWE-89), within the authentication component. This flaw allows an unauthenticated remote attacker to bypass security checks and achieve privileged user access.

Business impact

With a CVSS score of 8.6, this vulnerability represents a high risk to infrastructure security. Unauthorized administrative access allows an attacker to manipulate power distribution settings, potentially causing physical damage to connected hardware or resulting in significant service outages.

Remediation

Immediate Action: Organizations must update the PADM firmware to a version beyond 20 as soon as the vendor makes such a release available, or contact Eaton support for specific guidance on upgrading from end of life hardware.

Proactive Monitoring: Review authentication logs for suspicious login patterns or repeated failed attempts from unauthorized IP addresses.

Compensating Controls: Place the management interface of the PADM device behind a secure VPN or restricted management network to prevent direct exposure to the public internet.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability is critical due to the ease of exploitation and the level of access granted to an attacker. Administrators should immediately isolate affected devices from public networks and coordinate with Eaton to obtain necessary firmware updates or transition to supported hardware.