← Back to browse · API

CVE-2025-50121

Severity
CRITICAL
CVSS
9.5
EPSS
0.1604
Risk score
43.61
CISA KEV
No
PoC
No
Published
2025-07-11
Modified
2025-11-03
First seen
2026-08-07
Aliases
EUVD-2025-21128, GHSA-4GH4-J9HH-74H5
Products
Schneider Electric:EcoStruxure™ IT Data Center Expert 8.3 ≤Prior to
Sources
euvd EUVD-2025-21128

Description

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when a malicious folder is created over the web interface HTTP when enabled. HTTP is disabled by default.

References