Junglewise Threat Intelligence

CVE-2025-13902: Schneider Electric Modicon Controllers XSS in Web Server

CVE-2025-13902 · Severity: medium · CVSS 5.4 · Published 2026-03-10

Vendors: Schneider Electric.

Executive brief

Schneider Electric Modicon controllers, which are used to manage industrial automation and machinery, are affected by a security vulnerability in their web management interface. An authenticated attacker could inject malicious code that executes in another user's browser when they interact with specific elements on the controller's web page. This could allow an attacker to perform unauthorized actions or steal session information from legitimate operators.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in the web server component of several Schneider Electric Modicon controllers. The flaw stems from improper neutralization of user-supplied input during web page generation. An authenticated attacker with low privileges can inject a malicious payload into the web server; when a victim (such as an administrator) hovers over the crafted element, the payload executes arbitrary JavaScript in the context of the victim's session. This can lead to session hijacking or unauthorized configuration changes. Schneider Electric has released firmware updates for M241 and M251 models to mitigate this issue.

Affected products

  • Schneider Electric Modicon M241 Firmware versions prior to 5.4.13.12
  • Schneider Electric Modicon M251 Firmware versions prior to 5.4.13.12
  • Schneider Electric Modicon M258 Firmware All versions
  • Schneider Electric Modicon LMC058 Firmware All versions

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: advisory
  • 2026-03-10: patched: Patches available for M241/M251; M258/LMC058 status listed as affected.

References

Related threats