Summary
CVE-2026-22620 is an authentication bypass vulnerability, rooted in SQL injection (CWE-89), in Eaton’s Tripp Lite series PowerAlert Device Manager (PADM) firmware. Improper input validation in the authentication component lets an unauthenticated remote attacker bypass authentication and obtain privileged user access to the device. It is rated HIGH severity (CVSS 8.6).
Technical details
- Root cause: improper neutralization of special elements used in an SQL command (CWE-89 SQL injection) within the authentication component of the PADM firmware.
- Trigger conditions: an unauthenticated attacker submits crafted input to the authentication component; no valid credentials and no user interaction are required.
- Attack vector: network (the device’s remote management interface).
- Impact: authentication bypass granting privileged user access to the device, with high impact to availability and limited impact to confidentiality and integrity.
Affected software
- Eaton Tripp Lite series PADM (PowerAlert Device Manager) firmware, versions 0 through 20 (all versions in this range).
Severity
- CVSS v3.1 base score: 8.6 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Mitigation and recommended actions
- Immediate: Consult Eaton’s vulnerability advisory and the Tripp Lite series PADM 20 end-of-life notice for vendor remediation and migration guidance, and apply the vendor’s recommended firmware/replacement path.
- If no patch: Restrict network access to the device’s management interface. Place affected devices on isolated management networks or behind a firewall/VPN, block exposure to the public internet, and limit access to trusted administrative hosts only.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
PowerAlert Device Manager - Favicon fingerprint:
1860563962,2023156740

