Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Multiple Schneider Electric Vulnerabilities Let Attackers Inject OS Commands

Multiple Schneider Electric Vulnerabilities Let Attackers Inject OS Commands

Posted on July 10, 2025July 10, 2025 By CWS

Schneider Electrical has disclosed a crucial set of six vulnerabilities affecting its EcoStruxure IT Information Middle Professional software program that would permit attackers to execute distant code and achieve unauthorized system entry.

The vulnerabilities, found in variations 8.3 and prior, current vital safety dangers to information middle operations worldwide.

Probably the most extreme vulnerability, tracked as CVE-2025-50121, carries an ideal CVSS rating of 10.0 and allows unauthenticated distant code execution via OS command injection.

This crucial flaw happens when malicious actors create specifically crafted folders by way of the net interface when HTTP is enabled, although the protocol is disabled by default.

Further vulnerabilities embody inadequate entropy in password era (CVE-2025-50122), code injection via hostname manipulation (CVE-2025-50123), and server-side request forgery assaults (CVE-2025-50125).

Schneider Electrical analysts recognized these vulnerabilities via complete safety analysis performed by exterior researchers Jaggar Henry and Jim Becher from KoreLogic, Inc.

The corporate has acknowledged the severity of those findings and launched detailed technical documentation outlining the assault vectors and potential impacts.

The vulnerabilities collectively have an effect on the EcoStruxure IT Information Middle Professional platform, which serves as scalable monitoring software program for crucial infrastructure gear throughout quite a few industrial environments.

OS Command Injection Mechanism

The first assault vector facilities on CVE-2025-50121’s OS command injection vulnerability, which exploits improper neutralization of particular components in system instructions.

When HTTP is enabled on the net interface, attackers can manipulate folder creation processes to inject malicious instructions immediately into the underlying working system.

This system bypasses customary enter validation mechanisms and grants fast system-level entry with out authentication necessities.

The vulnerability manifests when the appliance processes user-supplied folder names with out correct sanitization, permitting shell metacharacters to be interpreted as system instructions.

As an illustration, folder names containing semicolons, pipes, or backticks can escape of the meant command context and execute arbitrary code with system privileges.

CVE IDCVSS v3.1 ScoreCVSS v4.0 ScoreVulnerability TypeAttack VectorCVE-2025-5012110.0 (Vital)9.5 (Vital)OS Command InjectionNetworkCVE-2025-501228.3 (Excessive)8.9 (Excessive)Inadequate EntropyAdjacent NetworkCVE-2025-501237.2 (Excessive)7.2 (Excessive)Code InjectionPhysicalCVE-2025-501257.2 (Excessive)6.3 (Medium)Server-Aspect Request ForgeryNetworkCVE-2025-501246.9 (Medium)7.2 (Excessive)Privilege ManagementPhysicalCVE-2025-64386.8 (Medium)5.9 (Medium)XML Exterior EntityNetwork

Organizations should instantly improve to EcoStruxure IT Information Middle Professional model 9.0, which addresses all recognized vulnerabilities.

As interim mitigation, directors ought to disable HTTP entry and implement community segmentation controls following Schneider Electrical’s cybersecurity greatest practices handbook.

Examine dwell malware conduct, hint each step of an assault, and make sooner, smarter safety selections -> Attempt ANY.RUN now

Cyber Security News Tags:Attackers, Commands, Electric, Inject, Multiple, Schneider, Vulnerabilities

Post navigation

Previous Post: US Sanction Key Threat Actors Linked With North Korea’s Remote IT Worker Scheme
Next Post: Android Packer Ducex Employs Serious Obfuscation Techniques and Detects Analysis Tools Presence

Related Posts

Hackers Use ClickFix Technique to Deploy NetSupport RAT via Compromised WordPress Sites Hackers Use ClickFix Technique to Deploy NetSupport RAT via Compromised WordPress Sites Cyber Security News
Tor Browser 15.0.1 Released With Fix for Multiple Security Vulnerabilities Tor Browser 15.0.1 Released With Fix for Multiple Security Vulnerabilities Cyber Security News
Prometei Botnet Attacking Linux Servers to Mine Cryptocurrency Prometei Botnet Attacking Linux Servers to Mine Cryptocurrency Cyber Security News
CISA Alerts to Exploited SolarWinds Serv-U Vulnerability CISA Alerts to Exploited SolarWinds Serv-U Vulnerability Cyber Security News
AI-powered Pentesting Tool ‘Villager’ Combines Kali Linux Tools with DeepSeek AI for Automated Attacks AI-powered Pentesting Tool ‘Villager’ Combines Kali Linux Tools with DeepSeek AI for Automated Attacks Cyber Security News
DOGE Accused of Creating Live Copy of the Country’s Social Security Information in Unsecured Cloud Environment DOGE Accused of Creating Live Copy of the Country’s Social Security Information in Unsecured Cloud Environment Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark