CVE-2026-22621
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated
CVSS
8.3
Alto
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 30 jul 2026 · Última mod.: 30 jul 2026 · CWE-78
Sin historial EPSS suficiente todavía.
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
- www.eaton.comhttps://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/eaton-vulnerability-advisory.pdf
- www.eaton.comhttps://www.eaton.com/content/dam/eaton/products/backup-power-ups-surge-it-power-distribution/eol/secure/eaton-tripp-lite-series-padm-20-eol-notice.pdf
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-226228.8 ALT—
——0Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.5hCVE-2026-441067.8 ALT—
——0A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.9hCVE-2026-440997.8 ALT—
——0A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.9hCVE-2026-440988.6 ALT—
——0This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.9hCVE-2026-440967.8 ALT—
——0A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.9hCVE-2026-440957.8 ALT—
——0A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.9h