Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead into an attacker with local access to execute unauthorized code or commands. This security issue has been fixed in the latest version of Galileo which is available on the Eaton download center.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 27 Nov 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead into an attacker with local access to execute unauthorized code or commands. This security issue has been fixed in the latest version of Galileo which is available on the Eaton download center. | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Eaton
Published:
Updated: 2025-11-27T10:48:41.850Z
Reserved: 2025-09-23T08:34:05.390Z
Link: CVE-2025-59890
No data.
Status : Received
Published: 2025-11-27T11:15:48.080
Modified: 2025-11-27T11:15:48.080
Link: CVE-2025-59890
No data.
OpenCVE Enrichment
No data.