CVE Database
/

CVE-2025-11739

Back to search

CVE-2025-11739

Published: Mar 10, 2026

Modified: Mar 10, 2026

PUBLISHED

Description

CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.

VendorProductVersions

Schneider Electric

EcoStruxure™ Power Monitoring Expert (PME)

affected
Version 2022
affected
Version 2023
affected
Version 2023 R2
affected
Version 2024
affected
Version 2024 R2

Schneider Electric

EcoStruxure™ Power Operation (EPO) Advanced Reporting and Dashboards Module

affected
Version 2022
affected
Version 2024

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now