Tripplite manufactures power distribution and uninterruptible power supply equipment, with observed vulnerabilities clustering in firmware and device-management interfaces across products such as the PDUMH15AT power distribution unit and SU2200RTXL2UA battery backup system. The recurring weakness classes—improper authentication and cross-site scripting in web-based management interfaces—reflect the attack surface inherent to networked infrastructure appliances that require remote administration and configuration. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tripplite over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16261CRITICAL Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin passwo | Sep 12, 2019 | 9.1 | 28 | NO | NO |
CVE-2020-26801MEDIUM A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with firmware version 12.04.0055. This vulnerability allows auth | Jun 25, 2021 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tripplite.
Media articles that mention a CVE ID that affects a product developed by Tripplite — matched by CVE ID, not by vendor name.