5.7
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L
Description
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton
Network M3
which is available on the Eaton download center.
Network M3
which is available on the Eaton download center.
Basic Information
ID
CVE-2026-22613
Source
Eaton
Published
Feb 9, 2026 at 05:39
Affected Product
Vendor
Eaton
Product
Network M3
Affected Versions
Eaton Network M3 0