CVE-2015-6461: Schneider Electric BMXNOC0401 Firmware

Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.

Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.

Affected products

Published 2019-03-21. Last modified 2026-06-17.