CVE-2025-59886
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
23/12/2025
Last modified:
23/12/2025
Description
Improper input validation at one of the endpoints of Eaton xComfort ECI&#39;s <br />
<br />
web interface, could lead into an attacker with network access to the device executing privileged user commands. As cybersecurity<br />
standards continue to evolve and to meet our requirements today, Eaton has decided to discontinue the<br />
product. Upon retirement or end of support, there will be no new security updates, non-security<br />
updates, or paid assisted support options, or online technical content updates.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH



