CVE-2025-54925
7.5Schneider Electric · EcoStruxure Power Monitoring Expert and EcoStruxure Power Operation
A Server-Side Request Forgery vulnerability in Schneider Electric EcoStruxure products allows unauthenticated attackers to access sensitive data by configuring the application to request malicious URLs.
Executive summary
A critical Server-Side Request Forgery vulnerability in Schneider Electric EcoStruxure power management software allows unauthenticated remote attackers to bypass security controls and access sensitive information.
Vulnerability
This flaw is a Server-Side Request Forgery (CWE-918) that occurs because the application improperly validates user-supplied URLs. An unauthenticated attacker can exploit this to force the server to make unauthorized requests to internal or external resources.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation allows an attacker to interact with internal network services that are otherwise protected from the internet, potentially leading to the exposure of sensitive operational data or unauthorized information disclosure.
Remediation
Immediate Action: Review the official security notice SEVD-2025-224-02 provided by Schneider Electric and apply all recommended firmware or software patches as soon as they become available.
Proactive Monitoring: Monitor network traffic for unusual outbound requests originating from the EcoStruxure server, specifically looking for connections to unauthorized external domains or internal sensitive subnets.
Compensating Controls: Deploy a Web Application Firewall or egress filtering rules to restrict the server from initiating unauthorized network connections to internal or untrusted external endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for unauthorized data access and the unauthenticated nature of the attack vector, organizations running affected Schneider Electric software must prioritize this vulnerability. Administrators should monitor the vendor security portal for patch releases and restrict network access to these interfaces to minimize the attack surface until updates are applied.