CVE-2025-2440: Schneider Electric Trio Q Licensed Data Radio
Medium severity, CVSS 4.2. EPSS: 0.2% chance of exploitation in the next 30 days.
CWE-922: Insecure Storage of Sensitive Information vulnerability exists that could potentially lead to unauthorized access of confidential data when a malicious user, having physical access and advanced information on the file system, sets the radio in factory default mode.
Affected products
- Schneider Electric Trio Q Licensed Data Radio: before v2.7.2 (fixed in v2.7.2)
Published 2025-04-09. Last modified 2026-06-17.