CVE-2025-54925
published 2025-08-20CVE-2025-54925: CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures the…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.42%
34.1th percentile
CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures the application to access a malicious url.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_operation_advanced_reporting_and_dashboards_module | — | — |
| schneider_electric | ecostruxure_power_operation_advanced_reporting_and_dashboards_module | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric EcoStruxure (Update B)
cisa_ics·2025-11-18·CVSS 7.5
[HIGH] Schneider Electric EcoStruxure (Update B)
ICS Advisory
##
Schneider Electric EcoStruxure (Update B)
Last RevisedNovember 18, 2025
Alert CodeICSA-25-224-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: EcoStruxure Power Monitoring Expert Software (PME), Power Operation (EPO), and Power SCADA Operation (PSO)
- Vulnerabilities: Deserialization of Untrusted Data, Server-Side Request Forgery (SSRF), Path Traversal
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow unauthorized access to sensitive data or remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Schneid
GHSA
GHSA-7c36-9fqm-vmxf: CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures th
ghsa_unreviewed·2025-08-20
CVE-2025-54925 [HIGH] CWE-918 GHSA-7c36-9fqm-vmxf: CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures th
CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures the application to access a malicious url.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-20
Published