CVE-2025-9997 MEDIUM

CVE-2025-9997

Vendor Schneider Electric
Product Saitel DR RTU
Weakness CWE-78
Published September 9, 2025
Last update September 10, 2025

CVSS base score

5.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.

Key dates

02Disclosure timeline

September 9, 2025 CVE published
September 10, 2025 Record updated