CVE-2026-77120
8.7Schneider Electric · PowerLogic T300
An OS Command Injection vulnerability in Schneider Electric PowerLogic T300 allows an authenticated user with SSH access to escalate privileges to root and execute unauthorized administrative functions.
Executive summary
A high-severity OS command injection vulnerability in Schneider Electric PowerLogic T300 allows authenticated attackers with SSH access to achieve full root-level compromise of the device.
Vulnerability
This is an OS command injection flaw (CWE-78) occurring within the operating system console. It specifically requires an authenticated user with SSH access to provide malicious input, which the system fails to sanitize, resulting in elevated privileges and arbitrary command execution.
Business impact
The vulnerability carries a CVSS score of 8.7, reflecting a high risk of total system compromise. Successful exploitation grants an attacker root-level access, allowing for complete control over the power management device, which could lead to unauthorized configuration changes, service disruption, or the potential for lateral movement within the industrial control environment.
Remediation
Immediate Action: Review the official Schneider Electric security notice (SEVD-2026-251-02) and apply any available firmware updates or vendor-recommended configuration changes immediately.
Proactive Monitoring: Monitor SSH authentication logs for unusual command patterns or attempts to execute system-level utilities by non-administrative accounts.
Compensating Controls: Restrict SSH access to the device to only authorized jump hosts or specific management subnets, and disable SSH services entirely if they are not required for daily operations.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the capability for root-level escalation, organizations using the PowerLogic T300 must prioritize this vulnerability. Administrators should audit current SSH access policies and ensure that only essential personnel retain such privileges until a vendor-supplied patch is successfully deployed.
More Schneider Electric CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section