CVE-2019-16261: Tripplite PDUMH15AT Firmware

Critical severity, CVSS 9.1. EPSS: 2.8% chance of exploitation in the next 30 days.

Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NOTE: the vendor's position is that a newer firmware version, fixing this vulnerability, had already been released before this vulnerability report about 12.04.0053.

Affected products

  • Tripplite PDUMH15AT Firmware: version 12.04.0053 only

Published 2019-09-12. Last modified 2026-06-17.