CVE-2025-2442: Schneider Electric Trio Q Licensed Data Radio

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could potentially lead to unauthorized access which could result in the loss of confidentially, integrity and availability when a malicious user, having physical access, sets the radio to the factory default mode.

Affected products

Published 2025-04-09. Last modified 2026-06-17.