CVE-2025-6625: Schneider Electric BMXNGD0100: m580 Global Data Module
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device.
Affected products
- Schneider Electric BMXNGD0100: m580 Global Data Module: any version
- Schneider Electric BMXNOC0401: Modicon m340 x80 Ethernet Communication Modules: any version
- Schneider Electric BMXNOE0100: Modbus/tcp Ethernet Modicon m340 Module: before 3.60 (fixed in 3.60)
- Schneider Electric BMXNOE0110: Modbus/tcp Ethernet Modicon m340 Factorycast Module: before 6.80 (fixed in 6.80)
- Schneider Electric BMXNOR0200H: Ethernet / Serial Rtu Module: any version
- Schneider Electric Modicon m340: any version
Published 2025-08-18. Last modified 2026-06-17.