GPU VulnDB

Database/Firmware, BMC & network fabric

Eaton UPS Companion (EUC) software installer: The installer does not properly authenticate the library files it loads

CVE-2025-59887Firmware, BMC & network fabricETN-VA-2025-1026curated

Impact

The installer does not properly authenticate the library files it loads, so an attacker who can place a file alongside the installation package gets arbitrary code execution during install - at whatever privilege the installer runs with, which is administrative. The exposure window is your own deployment process.

Who can reach it

An attacker with write access to wherever the installation package is staged - a shared drive, a downloads folder, an imaging share.

What to do

Use the fixed EUC version from Eaton's download centre and stage installers somewhere with restricted write access. Verify package hashes before running. Companion issues CVE-2025-59888 (unquoted search path) and CVE-2025-67450 (insecure library loading) have the same fix and the same mitigation.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.