CVE-2025-50125: Schneider Electric Ecostruxure It Data Center Expert
Medium severity, CVSS 6.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URLs and manipulation of host request header.
Affected products
- Schneider Electric Ecostruxure It Data Center Expert
Published 2025-07-11. Last modified 2026-06-17.