CVE-2025-7746

MEDIUM

Schneider Electric Altivar Process Drives - Cross-Site Scripting

Title source: llm
STIX 2.1

Description

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause an unvalidated data injected by a malicious user potentially leading to modify or read data in a victim’s browser.

Scores

CVSS v4 5.3
EPSS 0.0040
EPSS Percentile 31.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (8)
Schneider Electric/ATS490 Altivar Soft Starter all versions
Schneider Electric/ATV340E Altivar Machine Drives all versions
Schneider Electric/ATV6000 Medium Voltage Altivar Process Drives all versions
Schneider Electric/ATV630/650/660/680/6A0/6B0/6L0 Altivar Process Drives all versions
Schneider Electric/ATV930/950/955/960/980/9A0/9B0/9L0/991/992/993 Altivar Process Drives all versions
Schneider Electric/ILC992 InterLink Converter all versions
Schneider Electric/VW3A3530D: ATVdPAC module all versions - v25.0
Schneider Electric/VW3A3720 & VW3A3721 Altivar Process Communication Modules all versions
Published Sep 09, 2025
Tracked Since Feb 18, 2026