OS Command Injection Vulnerability in Schneider Electric Products
CVE-2025-50121
9.5CRITICAL
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 11 July 2025
What is CVE-2025-50121?
This vulnerability allows for unauthenticated remote code execution due to improper handling of special elements in OS commands. When a malicious folder is created through the web interface, which is typically disabled by default, an attacker can exploit this flaw. Proper controls and filters must be implemented to prevent such injection attacks, ensuring that the web interface remains secure against unauthorized actions.
Affected Version(s)
EcoStruxure IT Data Center Expert Versions v8.3 and prior