---
id: CVE-2025-67450
title: "Due to insecure library loading in the Eaton UPS Companion software executable,\_an attacker with access to the software package\n\n could perform arbitrary code execution .\_This security issue has been fixed in the latest version of EUC wh…"
summary: "Due to insecure library loading in the Eaton UPS Companion software executable,\_an attacker with access to the software package\n\n could perform arbitrary code execution .\_This security issue has been fixed in the latest version of EUC wh…"
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-427
vendor: eaton
product: ups_companion
affected:
  - ups_companion < 3.0
patched:
  - ups_companion 3.0
published: '2025-12-26'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T08:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67450'
references:
  - url: >-
      https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2025-1027.pdf
    label: CybersecurityCOE@eaton.com
tags:
  - nvd
epss: 0.00146
epssPercentile: 0.03279
ingestedAt: '2026-10-06T08:50:17.382Z'
---

## Overview

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package

 could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

## Affected

- `ups_companion < 3.0`

## Remediation

Upgrade past the affected range:

- `ups_companion 3.0`
