CVE-2025-54923: Schneider Electric Ecostruxure Power Monitoring Expert Pme

High severity, CVSS 8.7. EPSS: 0.7% chance of exploitation in the next 30 days.

CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization.

Affected products

  • Schneider Electric Ecostruxure Power Monitoring Expert Pme: version 2022 only; version 2023 only; version 2024 only; version 2024 R2 only
  • Schneider Electric Ecostruxure Power Operation Epo Advanced Reporting And Dashboards Module

Published 2025-08-20. Last modified 2026-06-17.