CVE-2021-22784: Schneider Electric C-Bus Toolkit
Medium severity, CVSS 5.7. EPSS: 12.1% chance of exploitation in the next 30 days.
A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.
Affected products
- Schneider Electric C-Bus Toolkit: before 1.15.9 (fixed in 1.15.9)
Published 2021-07-21. Last modified 2026-06-17.