8.3
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Description
Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS.
Basic Information
ID
CVE-2025-48396
Source
Eaton
Published
Nov 3, 2025 at 07:57
Affected Product
Vendor
Eaton
Product
Eaton Brightlayer Software Suite (BLSS)
Affected Versions
Eaton Eaton Brightlayer Software Suite (BLSS) 0