CVE-2025-11565: Schneider Electric Powerchute Serial Shutdown
High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause elevated system access when a Web Admin user on the local network tampers with the POST /REST/UpdateJRE request payload.
Affected products
- Schneider Electric Powerchute Serial Shutdown: up to and including v1.3
Published 2025-11-12. Last modified 2026-06-17.