πŸ” CVE Alert

CVE-2025-13902

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victim hovers over a maliciously crafted element on a web server containing the injected payload.

CWE CWE-79
Vendor schneider electric
Product modicon controllers m241/m251
Published Mar 10, 2026
Last Updated Mar 10, 2026
Stay Ahead of the Next One

Get instant alerts for schneider electric modicon controllers m241/m251

Be the first to know when new unknown vulnerabilities affecting schneider electric modicon controllers m241/m251 are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

Schneider Electric / Modicon Controllers M241/M251
Versions prior to 5.4.13.12
Schneider Electric / Modicon Controllers M258/LMC058
All versions

References

NVD β†— CVE.org β†— EPSS Data β†—
download.schneider-electric.com: https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-069-02.pdf