OS Command Injection Vulnerability in Schneider Electric Products
CVE-2025-50121

9.5CRITICAL

What is CVE-2025-50121?

This vulnerability allows for unauthenticated remote code execution due to improper handling of special elements in OS commands. When a malicious folder is created through the web interface, which is typically disabled by default, an attacker can exploit this flaw. Proper controls and filters must be implemented to prevent such injection attacks, ensuring that the web interface remains secure against unauthorized actions.

Affected Version(s)

EcoStruxure IT Data Center Expert Versions v8.3 and prior

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.