CVE-2025-2875: Schneider Electric Modicon Controllers m241 / m251
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality when an unauthenticated attacker manipulates controller’s webserver URL to access resources.
Affected products
- Schneider Electric Modicon Controllers m241 / m251: before v5.3.12.48 (fixed in v5.3.12.48)
- Schneider Electric Modicon Controllers m258 / LMC058: any version
Published 2025-05-14. Last modified 2026-06-17.