CVE-2025-6625
CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device.
- Published Aug 18, 2025
- CVSS 8.7 high
- 0.5% chance of exploitation in the next 30 days (EPSS)
Affected software
- Schneider ELectric BMXNOR0200H: Ethernet / Serial RTU Module
- Schneider Electric BMXNGD0100: M580 Global Data module
- Schneider Electric BMXNOC0401: Modicon M340 X80 Ethernet Communication modules
- Schneider Electric BMXNOE0100: Modbus/TCP Ethernet Modicon M340 module
- Schneider Electric BMXNOE0110: Modbus/TCP Ethernet Modicon M340 FactoryCast module
- Schneider Electric Modicon M340