Improper Authentication Vulnerability in Eaton UPS Companion Software
CVE-2025-59887

8.6HIGH

Key Information:

Vendor

Eaton

Vendor
CVE Published:
26 December 2025

What is CVE-2025-59887?

A security vulnerability exists in the Eaton UPS Companion software installer due to improper authentication of library files. This flaw could allow an attacker with access to the software package to execute arbitrary code, potentially compromising system integrity. Eaton has responded by addressing this issue in the latest version of the EUC software, now available for download.

Affected Version(s)

Eaton UPS Companion Software 0 < 3.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59887 : Improper Authentication Vulnerability in Eaton UPS Companion Software