OS Command Injection Vulnerability in Software by Schneider Electric
CVE-2026-77120

8.7HIGH

Key Information:

Vendor
CVE Published:
9 September 2026

What is CVE-2026-77120?

A vulnerability exists in various Schneider Electric software products that allows for the improper handling of user-controlled inputs. This OS Command Injection flaw poses a risk for privilege escalation to root, enabling unauthorized administrative actions when an authenticated user accesses the operating system console with SSH enabled. It is crucial for users to understand the implications of this vulnerability and implement proper safeguards to prevent exploitation.

Affected Version(s)

PowerLogic T300 Versions 2.9.8-5620 and prior

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.