OS Command Injection Vulnerability in BLMon Console by Schneider Electric
CVE-2025-9996
5.8MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-9996?
An OS Command Injection vulnerability exists in the BLMon Console, allowing an attacker to execute arbitrary shell commands during an SSH session when running a netstat command. This flaw arises due to improper neutralization of special elements, potentially leading to unauthorized access or control over the system.
Affected Version(s)
Saitel DP RTU all versions <= 11.06.33
Saitel DR RTU all versions <= 11.06.29
References
CVSS V4
Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved