Path traversal in EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module and EcoStruxure Power Monitoring Expert - CVE-2025-54926
Published: September 8, 2025
Vulnerability identifier: #VU114972
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54926
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote administrator can send a specially crafted HTTP request and upload arbitrary files on the system, leading to arbitrary code execution.
Affected software
EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module
EcoStruxure Power Monitoring Expert
EcoStruxure Power Monitoring Expert
How to mitigate CVE-2025-54926
Install updates from vendor's website.
EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module - addressed in versions Hotfix_269476_Release_13.1, Hotfix_269509_Release_13.1
EcoStruxure Power Monitoring Expert - addressed in versions Hotfix_269476_Release_13.1, Hotfix_269509_Release_13.1
EcoStruxure Power Monitoring Expert - addressed in versions Hotfix_269476_Release_13.1, Hotfix_269509_Release_13.1