CVE-2025-2441: Schneider Electric Trio Q Licensed Data Radio
Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could lead to loss of confidentiality when a malicious user, having physical access, sets the radio in factory default mode where the product does not correctly initialize all data.
Affected products
- Schneider Electric Trio Q Licensed Data Radio: before v2.7.2 (fixed in v2.7.2)
Published 2025-04-09. Last modified 2026-06-17.