CVE-2025-2875: Schneider Electric Modicon Controllers m241 / m251

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality when an unauthenticated attacker manipulates controller’s webserver URL to access resources.

Affected products

Published 2025-05-14. Last modified 2026-06-17.