CVE-2025-3116: Schneider Electric Modicon Controllers m241/m251
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends special malformed HTTPS request containing improper formatted body data to the controller.
Affected products
- Schneider Electric Modicon Controllers m241/m251: before 5.3.12.51 (fixed in 5.3.12.51)
- Schneider Electric Modicon Controllers m258 / LMC058: any version
Published 2025-06-10. Last modified 2026-06-17.