---
id: CVE-2025-59888
title: >-
  Improper quotation in search paths in the Eaton UPS Companion software
  installer could lead to arbitrary code execution of an attacker with the
  access to the 


  file system
summary: >-
  Improper quotation in search paths in the Eaton UPS Companion software
  installer could lead to arbitrary code execution of an attacker with the
  access to the 


  file system.  This security issue has been fixed in the latest version of EUC…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H'
cwe:
  - CWE-428
vendor: eaton
product: ups_companion
affected:
  - ups_companion < 3.0
patched:
  - ups_companion 3.0
published: '2025-12-26'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T08:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59888'
references:
  - url: >-
      https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2025-1026.pdf
    label: CybersecurityCOE@eaton.com
tags:
  - nvd
epss: 0.00189
epssPercentile: 0.07684
ingestedAt: '2026-10-06T08:50:17.381Z'
---

## Overview

Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the 

file system.  This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

## Affected

- `ups_companion < 3.0`

## Remediation

Upgrade past the affected range:

- `ups_companion 3.0`
