CVE-2021-22720: Schneider Electric C-Bus Toolkit
High severity, CVSS 7.2. EPSS: 30.5% chance of exploitation in the next 30 days.
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring a project.
Affected products
- Schneider Electric C-Bus Toolkit: up to and including 1.15.7
Published 2021-04-13. Last modified 2026-06-17.