What is CVE-2026-22620?
An Improper Input Validation vulnerability in the authentication component of Eaton's Tripp Lite series PAD/PADM firmware has been discovered. This allows an unauthenticated remote attacker to bypass authentication and gain privileged user access to the device. Upgrading the firmware to the latest version is recommended.
Azərbaycanca: Eaton Tripp Lite PAD/PADM cihazlarının autentifikasiya komponentində daxiletmə yoxlaması zəifliyi (Improper Input Validation) aşkarlanıb. Bu boşluq autentifikasiya olunmamış uzaqdan təcavüzkara identifikasiyanı keçərək cihaza imtiyazlı istifadəçi girişi əldə etməyə imkan verir. Cihazın proqram təminatını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20; shared vendor: Eaton
FAQ2
What type of vulnerability was discovered in Eaton Tripp Lite PAD/PADM devices?
An Improper Input Validation vulnerability was discovered in these devices.
What can an attacker achieve by exploiting this vulnerability?
An unauthenticated remote attacker can bypass authentication and gain privileged user access to the device.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.