Cross-site Scripting Vulnerability in Schneider Electric Products
CVE-2025-7746
5.3MEDIUM
Key Information:
- Vendor
Schneider Electric
- Status
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-7746?
A Cross-site Scripting (XSS) vulnerability exists in certain Schneider Electric web applications due to improper neutralization of user input during page generation. This security flaw allows an attacker to inject unvalidated data into the web application, potentially enabling them to execute scripts in a victim's browser session. As a result, sensitive information may be accessed or modified without the user's consent, highlighting the importance of implementing strict input validation and sanitization measures.
Affected Version(s)
ATS490 Altivar Soft Starter all versions
ATV340E Altivar Machine Drives all versions
ATV6000 Medium Voltage Altivar Process Drives all versions