CVE-2025-9997: Schneider Electric Saitel Dp Rtu

Medium severity, CVSS 5.8. EPSS: 0.5% chance of exploitation in the next 30 days.

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.

Affected products

Published 2025-09-09. Last modified 2026-06-17.