Path traversal in EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module and EcoStruxure Power Monitoring Expert - CVE-2025-54926

 

Path traversal in EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module and EcoStruxure Power Monitoring Expert - CVE-2025-54926

Published: September 8, 2025


Vulnerability identifier: #VU114972
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54926
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote administrator can send a specially crafted HTTP request and upload arbitrary files on the system, leading to arbitrary code execution.


Affected software

EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module
EcoStruxure Power Monitoring Expert

How to mitigate CVE-2025-54926

Install updates from vendor's website.

EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module - addressed in versions Hotfix_269476_Release_13.1, Hotfix_269509_Release_13.1
EcoStruxure Power Monitoring Expert - addressed in versions Hotfix_269476_Release_13.1, Hotfix_269509_Release_13.1

External References

Related Security Bulletins