CVE-2025-54926
published 2025-08-20CVE-2025-54926: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution when an…
PriorityP347high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.85%
54.0th percentile
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution when an authenticated attacker with admin privileges uploads a malicious file over HTTP which then gets executed.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_operation_advanced_reporting_and_dashboards_module | — | — |
| schneider_electric | ecostruxure_power_operation_advanced_reporting_and_dashboards_module | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9q86-673r-39p8: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution whe
ghsa_unreviewed·2025-08-20
CVE-2025-54926 [HIGH] CWE-22 GHSA-9q86-673r-39p8: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution whe
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution when an authenticated attacker with admin privileges uploads a malicious file over HTTP which then gets executed.
CISA ICS
Schneider Electric EcoStruxure (Update B)
cisa_ics·2025-11-18·CVSS 7.5
[HIGH] Schneider Electric EcoStruxure (Update B)
ICS Advisory
##
Schneider Electric EcoStruxure (Update B)
Last RevisedNovember 18, 2025
Alert CodeICSA-25-224-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: EcoStruxure Power Monitoring Expert Software (PME), Power Operation (EPO), and Power SCADA Operation (PSO)
- Vulnerabilities: Deserialization of Untrusted Data, Server-Side Request Forgery (SSRF), Path Traversal
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow unauthorized access to sensitive data or remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Schneid
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-20
Published