CVE-2025-50121: Schneider Electric Ecostruxure It Data Center Expert

Critical severity, CVSS 9.5. EPSS: 19.4% chance of exploitation in the next 30 days.

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when a malicious folder is created over the web interface HTTP when enabled. HTTP is disabled by default.

Affected products

Published 2025-07-11. Last modified 2026-06-17.