Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-59886

Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-20 Validación incorrecta de entrada
Fecha de publicación:
23/12/2025
Última modificación:
23/12/2025

Descripción

*** Pendiente de traducción *** Improper input validation at one of the endpoints of Eaton xComfort ECI&amp;#39;s <br /> <br /> web interface, could lead into an attacker with network access to the device executing privileged user commands. As cybersecurity<br /> standards continue to evolve and to meet our requirements today, Eaton has decided to discontinue the<br /> product. Upon retirement or end of support, there will be no new security updates, non-security<br /> updates, or paid assisted support options, or online technical content updates.