Path traversal in EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module and EcoStruxure Power Monitoring Expert - CVE-2025-54926
Published: September 8, 2025
Vulnerability identifier: #VU114972
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-54926
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Schneider Electric
Affected software:
EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module
EcoStruxure Power Monitoring Expert
EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module
EcoStruxure Power Monitoring Expert
Detailed vulnerability description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote administrator can send a specially crafted HTTP request and upload arbitrary files on the system, leading to arbitrary code execution.
How to mitigate CVE-2025-54926
Install updates from vendor's website.