OS Command Injection Vulnerability in Software by Schneider Electric
CVE-2026-77120
8.7HIGH
What is CVE-2026-77120?
A vulnerability exists in various Schneider Electric software products that allows for the improper handling of user-controlled inputs. This OS Command Injection flaw poses a risk for privilege escalation to root, enabling unauthorized administrative actions when an authenticated user accesses the operating system console with SSH enabled. It is crucial for users to understand the implications of this vulnerability and implement proper safeguards to prevent exploitation.
Affected Version(s)
PowerLogic T300 Versions 2.9.8-5620 and prior