CVE-2025-7746
MEDIUMSchneider Electric Altivar Process Drives - Cross-Site Scripting
Title source: llmDescription
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause an unvalidated data injected by a malicious user potentially leading to modify or read data in a victim’s browser.
References (2)
Core 2
Scores
CVSS v4
5.3
EPSS
0.0040
EPSS Percentile
31.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (8)
Schneider Electric/ATS490 Altivar Soft Starter
all versions
Schneider Electric/ATV340E Altivar Machine Drives
all versions
Schneider Electric/ATV6000 Medium Voltage Altivar Process Drives
all versions
Schneider Electric/ATV630/650/660/680/6A0/6B0/6L0 Altivar Process Drives
all versions
Schneider Electric/ATV930/950/955/960/980/9A0/9B0/9L0/991/992/993 Altivar Process Drives
all versions
Schneider Electric/ILC992 InterLink Converter
all versions
Schneider Electric/VW3A3530D: ATVdPAC module
all versions - v25.0
Schneider Electric/VW3A3720 & VW3A3721 Altivar Process Communication Modules
all versions
Published
Sep 09, 2025
Tracked Since
Feb 18, 2026