{"id":"CVE-2025-67450","title":"Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package\n\n could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC wh…","summary":"Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package\n\n could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC wh…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-427"],"vendor":"eaton","product":"ups_companion","affected":["ups_companion < 3.0"],"patched":["ups_companion 3.0"],"published":"2025-12-26","updated":"2026-10-06","sourceUpdated":"2026-10-06T08:10:00.193","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-67450","references":[{"url":"https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2025-1027.pdf","label":"CybersecurityCOE@eaton.com"}],"tags":["nvd"],"epss":0.00146,"epssPercentile":0.03286,"ingestedAt":"2026-10-06T08:50:17.382Z","slug":"CVE-2025-67450","body":"## Overview\n\nDue to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package\n\n could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.\n\n## Affected\n\n- `ups_companion < 3.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `ups_companion 3.0`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}