Database/Firmware, BMC & network fabric

Eaton UPS Companion (EUC) software installer: The installer does not properly authenticate the library files it loads
Impact
The installer does not properly authenticate the library files it loads, so an attacker who can place a file alongside the installation package gets arbitrary code execution during install - at whatever privilege the installer runs with, which is administrative. The exposure window is your own deployment process.
Who can reach it
An attacker with write access to wherever the installation package is staged - a shared drive, a downloads folder, an imaging share.
What to do
Use the fixed EUC version from Eaton's download centre and stage installers somewhere with restricted write access. Verify package hashes before running. Companion issues CVE-2025-59888 (unquoted search path) and CVE-2025-67450 (insecure library loading) have the same fix and the same mitigation.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.