CVE-2025-41426
CVSS 9.8 CRITICAL: affected Vertiv products contain a stack based buffer overflow vulnerability. EPSS 0.8% (52nd percentile).
Vulnerabilities & Exploits
The weak point is the UPS management card, not the rack hardware. If an attacker gets into that admin plane, the card can become a control point for power continuity, which means a clean shutdown or stable uptime is no longer guaranteed.
Claroty’s Team82 found two critical flaws in Vertiv Liebert IS-UNITY-DP and RDU101 cards: an authentication bypass on the web interface and a stack-based buffer overflow that can lead to remote code execution. Vertiv says firmware is available in 1.9.1.2_0000001 for Liebert RDU101 and 8.4.3.1_00160 for IS-UNITY devices.
The operational risk is wider than a normal appliance bug. These cards sit in the path that keeps dependent systems online or shuts them down safely, so compromise can create a direct outage trigger across data center and critical infrastructure environments.
2 sources · Jun 11
CVSS 9.8 CRITICAL: affected Vertiv products contain a stack based buffer overflow vulnerability. EPSS 0.8% (52nd percentile).
CVSS 9.8 CRITICAL: affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass… EPSS 0.6% (45th percentile).
Industrial Cyber
Claroty finds authentication bypass, RCE flaws in Vertiv UPS management cards that could disrupt data center operations - Industrial Cyber
Claroty's Team82 finds authentication bypass, RCE flaws in Vertiv UPS management cards that could disrupt data center operations.
originalSecurityWeek
Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers
Claroty researchers have analyzed the security of Vertiv UPS network cards and the Trane Tracer SC+ HVAC controller.
originalPart of the PlainSec briefing for 2026-06-11
Every edition of this story: UPS Cards Become a Power-Control Risk