CVE-2025-11739: High severity Schneider-electric Ecostruxure Power Monitoring Expert vulnerability
CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11739?
CVE-2025-11739 has a severity rating of high with a CVSS score of 8.5.
What type of vulnerability is identified in CVE-2025-11739?
CVE-2025-11739 is a CWE-502 vulnerability related to the deserialization of untrusted data.
How do I fix CVE-2025-11739?
To mitigate CVE-2025-11739, ensure that the software versions of Schneider-electric Ecostruxure Power Monitoring Expert and Power Operation are updated to the latest patched versions.
Who is affected by CVE-2025-11739?
CVE-2025-11739 affects users of Schneider-electric Ecostruxure Power Monitoring Expert and Schneider-electric Ecostruxure Power Operation.
What is the potential impact of CVE-2025-11739?
CVE-2025-11739 could allow a locally authenticated attacker to execute arbitrary code with administrative privileges on the affected systems.