CVE-2025-1960: Schneider Electric Webhmi – Deployed With Ecostruxure Power Automation System
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to execute unauthorized commands when a system’s default password credentials have not been changed on first use. The default username is not displayed correctly in the WebHMI interface.
Affected products
- Schneider Electric Webhmi – Deployed With Ecostruxure Power Automation System: up to and including 2.6.30.19
Published 2025-03-12. Last modified 2026-06-17.