download.schneider-electric.com
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-069-02.pdf CVE-2025-13902
MEDIUM
Schneider Electric Modicon Controllers M241/M251/M258/LMC058 Stored Cross-Site Scripting
Record summary
CVE-2025-13902 has a selected CVSS score of 5.1 (medium).
Description
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victim hovers over a maliciously crafted element on a web server containing the injected payload.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Modicon Controllers M241/M251Browse Schneider Electric / Modicon Controllers M241/M251Default status: unaffected | CVE List | Versions prior to 5.4.13.12 | affected |
Modicon Controllers M258/LMC058Browse Schneider Electric / Modicon Controllers M258/LMC058Default status: unaffected | CVE List | All versions | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-13902