ZDI-CAN-28034: ZDI-26-212: Schneider Electric EcoStruxure Data Center Expert Hard-coded Password Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Data Center Expert. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-13957.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28034?
ZDI-CAN-28034 has a high severity rating due to its potential for remote code execution.
How do I fix ZDI-CAN-28034?
To fix ZDI-CAN-28034, you should update to the latest version of Schneider Electric EcoStruxure Data Center Expert where the vulnerability is addressed.
What types of attacks can be executed through ZDI-CAN-28034?
ZDI-CAN-28034 allows remote attackers to execute arbitrary code on affected systems.
Is authentication required to exploit ZDI-CAN-28034?
Yes, authentication is required for exploitation of ZDI-CAN-28034.
Which software is affected by ZDI-CAN-28034?
ZDI-CAN-28034 affects Schneider Electric EcoStruxure Data Center Expert installations.