5.8
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
Description
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause the execution of any shell command when executing a netstat command using BLMon Console in an SSH session.
Basic Information
ID
CVE-2025-9996
Source
schneider
Published
Sep 9, 2025 at 21:11
Affected Product
Vendor
Schneider Electric
Product
Saitel DR RTU
Version
all versions
Affected Versions
Schneider Electric Saitel DR RTU all versions
Schneider Electric Saitel DP RTU all versions
Schneider Electric Saitel DP RTU all versions