Vulnerability Description
Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device executing privileged user commands. As cybersecurity standards continue to evolve and to meet our requirements today, Eaton has decided to discontinue the product. Upon retirement or end of support, there will be no new security updates, non-security updates, or paid assisted support options, or online technical content updates.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eaton | Xcomfort Ethernet Communication Interface | All versions |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-59886?
CVE-2025-59886 is a vulnerability with a CVSS score of 8.8 (HIGH). Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device executing privileged user commands. As cybersec...
How severe is CVE-2025-59886?
CVE-2025-59886 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-59886?
Check the references section above for vendor advisories and patch information. Affected products include: Eaton Xcomfort Ethernet Communication Interface.