CVE-2026-22613: Eaton Network m3

Medium severity, CVSS 5.7. EPSS: 0.2% chance of exploitation in the next 30 days.

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton Network M3 which is available on the Eaton download center.

Affected products

  • Eaton Network m3: before 2.3.3 (fixed in 2.3.3)

Published 2026-02-09. Last modified 2026-06-17.