CVE-2026-22622

Eaton · Tripp Lite series PADM firmware

Eaton Tripp Lite series PADM firmware contains an OS command injection vulnerability in the session management interface, allowing authenticated users to escalate privileges.

Executive summary

An OS command injection vulnerability in Eaton Tripp Lite series PADM firmware allows authenticated attackers to escalate privileges and achieve full control over the device.

Vulnerability

The session management interface fails to properly neutralize special elements, resulting in OS command injection (CWE-78). An authenticated user can leverage this flaw to execute arbitrary commands at the system level.

Business impact

This vulnerability carries a CVSS score of 8.8, reflecting its potential to grant an attacker full control over critical power management infrastructure. Compromise of this device could lead to unauthorized physical or virtual access to connected IT environments, resulting in operational downtime or systemic instability.

Remediation

Immediate Action: Consult the official Eaton security advisory for available firmware updates and apply them as directed. If a patch is unavailable, restrict network access to the management interface to trusted administrative segments only.

Proactive Monitoring: Monitor device logs for anomalous command execution patterns or unexpected changes in user privilege levels.

Compensating Controls: Implement strict network segmentation and utilize a VPN or jump server to limit access to the PADM management interface.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Given the potential for complete device takeover, organizations using Eaton Tripp Lite series PADM units should treat this vulnerability with high urgency. Users must verify their current firmware version and apply the vendor-recommended update as soon as it is published.