Junglewise Threat Intelligence

CVE-2025-6625: Schneider Electric Modicon M340 improper input validation in FTP service

CVE-2025-6625 · Severity: high · CVSS 7.5 · Published 2026-09-17

Executive brief

Schneider Electric Modicon M340 controllers and communication modules contain an improper input validation flaw in the FTP service that allows remote attackers to trigger a denial-of-service condition by sending crafted FTP commands. Industrial facilities depend on these programmable automation controllers (PACs) to continuously monitor and control critical operations. An exploitation of this vulnerability could cause unplanned downtime in manufacturing, energy, water treatment, and chemical production systems, potentially leading to safety hazards, equipment damage, or disruption to essential services.

Technical details

A CWE-20 (Improper Input Validation) vulnerability exists in the FTP service implementation of Schneider Electric Modicon M340 controllers and associated communication modules (BMXNOR0200H, BMXNGD0100, BMXNOC0401, BMXNOE0100, BMXNOE0110). An unauthenticated remote attacker on the network can send a specially crafted FTP command to port 21 to trigger a denial-of-service condition, causing the device to become unavailable. The FTP service is disabled by default, but when enabled for administrative or remote maintenance purposes, the vulnerability becomes exploitable. Patches are available: BMXNOE0100 version 3.60, BMXNOE0110 version 6.80, Modicon M340 firmware version SV3.70, and BMXNOR0200H version SV1.7 IR27 include fixes. Devices without patched versions should disable FTP, implement firewall rules to block port 21, and apply network segmentation.

Affected products

  • Schneider Electric Modicon M340 Controller all versions prior to SV3.70
  • Schneider Electric BMXNOR0200H Ethernet/Serial RTU Module versions prior to SV1.7 IR27
  • Schneider Electric BMXNGD0100 M580 Global Data module all versions
  • Schneider Electric BMXNOC0401 Modicon M340 X80 Ethernet Communication modules all versions
  • Schneider Electric BMXNOE0100 Modbus/TCP Ethernet Modicon M340 module versions prior to 3.60
  • Schneider Electric BMXNOE0110 Modbus/TCP Ethernet Modicon M340 FactoryCast module versions prior to 6.80

Timeline

  • 2026-09-17: disclosed: CISA advisory ICSA-26-260-04 published
  • 2026-09-17: patched: Patches released for BMXNOE0100 (v3.60), BMXNOE0110 (v6.80), Modicon M340 (SV3.70), and BMXNOR0200H (SV1.7 IR27)

References