ZDI-25-829: (0Day) Schneider Electric EcoStruxure Power Monitoring Expert GetFilteredSinkProvider Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Monitoring Expert. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-54923.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-829?
ZDI-25-829 has been assigned a CVSS rating of 8.8, indicating a high severity level.
How can I fix ZDI-25-829?
To fix ZDI-25-829, apply the latest security updates provided by Schneider Electric for EcoStruxure Power Monitoring Expert.
What type of attacks can ZDI-25-829 facilitate?
ZDI-25-829 allows remote attackers to execute arbitrary code on affected installations.
Is authentication required to exploit ZDI-25-829?
Yes, authentication is required to exploit the ZDI-25-829 vulnerability.
Which software is affected by ZDI-25-829?
The vulnerability ZDI-25-829 affects Schneider Electric EcoStruxure Power Monitoring Expert installations.