CVE Explorer
CVE-2026-22620
Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"PADM","vendor":"Eaton","versions":[{"lessThanOrEqual":"20","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1e39a197a24992492c5276ce6b13ceebd92108b62e4d8b0d734c9db1ac0a9879 · sha256:6aade0d4fe30ceaa… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1e39a197a24992492c5276ce6b13ceebd92108b62e4d8b0d734c9db1ac0a9879 · sha256:6aade0d4fe30ceaa… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-89","description":"CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1e39a197a24992492c5276ce6b13ceebd92108b62e4d8b0d734c9db1ac0a9879 · sha256:6aade0d4fe30ceaa… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["vendor-advisory"],"url":"https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/eaton-va-2026-1005.pdf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1e39a197a24992492c5276ce6b13ceebd92108b62e4d8b0d734c9db1ac0a9879 · sha256:6aade0d4fe30ceaa… · /containers/cna/references/0
{"tags":["release-notes"],"url":"https://www.eaton.com/content/dam/eaton/products/backup-power-ups-surge-it-power-distribution/eol/secure/eaton-tripp-lite-series-padm-20-eol-notice.pdf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1e39a197a24992492c5276ce6b13ceebd92108b62e4d8b0d734c9db1ac0a9879 · sha256:6aade0d4fe30ceaa… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.