CVE-2025-67450
Insecure Library Loading in Eaton UPS Companion Enables Code Execution
Publication date: 2025-12-26
Last updated on: 2026-02-18
Assigner: Eaton
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| eaton | ups_companion | to 3.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-427 | The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is due to insecure library loading in the Eaton UPS Companion software executable. An attacker who has access to the software package could exploit this flaw to perform arbitrary code execution on the affected system.
How can this vulnerability impact me? :
The vulnerability can allow an attacker to execute arbitrary code with limited privileges on the affected system, potentially leading to complete compromise of confidentiality, integrity, and availability of the system.
What immediate steps should I take to mitigate this vulnerability?
Update the Eaton UPS Companion software to the latest version available on the Eaton download center, as this version contains the fix for the insecure library loading vulnerability.