Cross-site Scripting Vulnerability in Schneider Electric Products
CVE-2025-7746
Key Information:
- Vendor
Schneider Electric
- Status
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-7746?
A Cross-site Scripting (XSS) vulnerability exists in certain Schneider Electric web applications due to improper neutralization of user input during page generation. This security flaw allows an attacker to inject unvalidated data into the web application, potentially enabling them to execute scripts in a victim's browser session. As a result, sensitive information may be accessed or modified without the user's consent, highlighting the importance of implementing strict input validation and sanitization measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ATS490 Altivar Soft Starter all versions
ATV340E Altivar Machine Drives all versions
ATV6000 Medium Voltage Altivar Process Drives all versions
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved