CVE-2026-9717: Schneider Electric Powerlogic p7 Firmware
High severity, CVSS 7.2. EPSS: 1.7% chance of exploitation in the next 30 days.
CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service.
Affected products
- Schneider Electric Powerlogic p7 Firmware: before 02.004.001.000 (fixed in 02.004.001.000)
Published 2026-06-25. Last modified 2026-07-01.