CVE-2025-48396: Eaton Brightlayer Software Suite Blss

High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).

Affected products

  • Eaton Eaton Brightlayer Software Suite Blss: before 7.4 (fixed in 7.4)

Published 2025-11-03. Last modified 2026-06-17.