CVE-2015-7937: Schneider Electric BMXNOC0401

High severity, CVSS 10.0. EPSS: 7.4% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.

Affected products

Published 2015-12-21. Last modified 2026-06-17.