PT-2026-32672 · Apc · Powerchute Serial Shutdown

CVE-2026-2400

·

Published

2026-04-14

·

Updated

2026-04-19

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PowerChute Serial Shutdown (affected versions not specified)
Description Improper neutralization of CRLF sequences, also known as CRLF Injection, occurs when the application fails to properly filter carriage return and line feed characters. This issue can be triggered when a Web Admin user modifies the payload of the 'POST /setPCBEDesc' request, potentially leading to the reset of application user credentials or a denial of service condition via specially crafted POST requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05385
CVE-2026-2400

Affected Products

Powerchute Serial Shutdown