8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Description
CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific
crafted FTP command is sent to the device.
crafted FTP command is sent to the device.
Basic Information
ID
CVE-2025-6625
Source
schneider
Published
Aug 18, 2025 at 06:58
Affected Product
Vendor
Schneider Electric
Product
Modicon M340
Version
All versions
Affected Versions
Schneider Electric Modicon M340 All versions
Schneider ELectric BMXNOR0200H: Ethernet / Serial RTU Module All versions
Schneider Electric BMXNGD0100: M580 Global Data module All versions
Schneider Electric BMXNOC0401: Modicon M340 X80 Ethernet Communication modules All versions
Schneider Electric BMXNOE0100: Modbus/TCP Ethernet Modicon M340 module Versions prior to 3.60
Schneider Electric BMXNOE0110: Modbus/TCP Ethernet Modicon M340 FactoryCast module Versions prior to 6.80
Schneider ELectric BMXNOR0200H: Ethernet / Serial RTU Module All versions
Schneider Electric BMXNGD0100: M580 Global Data module All versions
Schneider Electric BMXNOC0401: Modicon M340 X80 Ethernet Communication modules All versions
Schneider Electric BMXNOE0100: Modbus/TCP Ethernet Modicon M340 module Versions prior to 3.60
Schneider Electric BMXNOE0110: Modbus/TCP Ethernet Modicon M340 FactoryCast module Versions prior to 6.80