ZDI-25-826: (0Day) Schneider Electric EcoStruxure Power Monitoring Expert ExportDataAsXML Server-Side Request Forgery Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Schneider Electric EcoStruxure Power Monitoring Expert. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-54925.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-826?
The severity of ZDI-25-826 is rated at 7.5 on the CVSS scale.
How do I fix ZDI-25-826?
To fix ZDI-25-826, it is recommended to apply the latest security patches provided by Schneider Electric for EcoStruxure Power Monitoring Expert.
Who can exploit ZDI-25-826?
ZDI-25-826 can be exploited by remote attackers without the need for authentication.
What kind of information can be disclosed by exploiting ZDI-25-826?
Exploiting ZDI-25-826 allows remote attackers to potentially disclose sensitive information from affected installations.
Which software is affected by ZDI-25-826?
ZDI-25-826 affects installations of Schneider Electric EcoStruxure Power Monitoring Expert.