CVE-2025-48393: Eaton g4 Pdu

Medium severity, CVSS 5.7. EPSS: 0.2% chance of exploitation in the next 30 days.

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton G4 PDU which is available on the Eaton download center.

Affected products

  • Eaton g4 Pdu: before 3.5.0 (fixed in 3.5.0)

Published 2025-08-06. Last modified 2026-06-17.