CVE-2025-46737: Schweitzer Engineering Laboratories Sel-5037 Grid Configurator
High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.
SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data gateway service in the application. This gateway service includes an API which is not properly configured to reject requests from unexpected sources.
Affected products
- Schweitzer Engineering Laboratories Sel-5037 Grid Configurator: before 6.4.0.58 (fixed in 6.4.0.58)
Published 2025-05-12. Last modified 2026-06-17.