Modicon M241, M251, M258, LMC058 Security Notification (CVE-2025-2875)
This document details a high-severity vulnerability (CVE-2025-2875) in Schneider Electric Modicon M241, M251, M258, and LMC058 programmable logic controllers, which could allow an unauthenticated attacker to read arbitrary files via webserver URL manipulation. It provides remediation steps, including firmware updates to versions v5.3.12.48 (M241/M251) and v5.0.4.19 (M258/LMC058), as well as mitigations such as network segmentation and webserver deactivation.
Failed to load PDF
Download insteadYou might also like
Security Expert Elevator Integration Guide
1 pages
Acti9 iID B-SI RCCB Protection for Photovoltaic Installations Customer Story
2 pages
Back-UPS SX3 800 and 1100 Specifications
2 pages
NetShelter 9000 Series Switched Rack PDU APDU9953 Specifications
2 pages
EcoFit Life Extension Solution for Medium Voltage Switchgear
2 pages
APC AP7802 Metered Rack PDU Specifications
2 pages
SP-MNR2 SecurityExpert COMMS Expander Manual
4 pages
NSYSQCR9080 Quick Fixing Cross Rails Data Sheet
2 pages
Satchwell 24V Modulating Actuators Specification
5 pages
VB-7000 Globe Valves with M900A Actuators Selection Guide
9 pages