CVE-2025-48393: Eaton g4 Pdu
Medium severity, CVSS 5.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton G4 PDU which is available on the Eaton download center.
Affected products
- Eaton g4 Pdu: before 3.5.0 (fixed in 3.5.0)
Published 2025-08-06. Last modified 2026-06-17.