Modicon M241, M251, M258, LMC058 Security Notification (CVE-2025-2875)
This document details a high-severity vulnerability (CVE-2025-2875) in Schneider Electric Modicon M241, M251, M258, and LMC058 programmable logic controllers, which could allow an unauthenticated attacker to read arbitrary files via webserver URL manipulation. It provides remediation steps, including firmware updates to versions v5.3.12.48 (M241/M251) and v5.0.4.19 (M258/LMC058), as well as mitigations such as network segmentation and webserver deactivation.
Failed to load PDF
Download insteadYou might also like
SpaceLogic UI-8/AO-V-4 and UI-8/AO-V-4-H Central IO Module Manual
7 pages
DEGL Duct Temperature Transmitter Technical Data
2 pages
Easy Modular Data Center ISO 40-Foot Technical Specification
38 pages
V232 Pressure-Balanced Two-Way Plug Valve Specification Sheet
4 pages
Intelligent Building Management Systems (iBMS) Overview
1 pages
EcoStruxure Panel Server Advanced PAS800 Tender Specification Guide
4 pages
EcoFit Life Extension Advanced for Sepam Series 20 with P5 Service Description
2 pages
Okken Intelligent Low-Voltage Switchboard Brochure
2 pages
Access 7 A Reader Series Specifications
1 pages
MG350S-24F SmartX Globe Valve Actuator Specification Sheet
4 pages