CVE-2025-11739: Schneider Electric Ecostruxure Power Monitoring Expert

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.

Affected products

  • Schneider Electric Ecostruxure Power Monitoring Expert: version 2022 only; version 2023 only; version 2024 only
  • Schneider Electric Ecostruxure Power Operation: version 2022 only; version 2024 only

Published 2026-03-10. Last modified 2026-06-24.