CVE-2025-9997: Schneider Electric Saitel Dp Rtu
Medium severity, CVSS 5.8. EPSS: 0.5% chance of exploitation in the next 30 days.
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.
Affected products
- Schneider Electric Saitel Dp Rtu: up to and including 11.06.33
- Schneider Electric Saitel Dr Rtu: up to and including 11.06.29
Published 2025-09-09. Last modified 2026-06-17.