Junglewise Threat Intelligence

CVE-2026-9718: Schneider Electric PowerLogic P7 reachable assertion in network service

CVE-2026-9718 · Severity: info · CVSS 6.9 · Published 2026-06-25

Technologies: Schneider Electric PowerLogic P7. Vendors: Schneider Electric.

Executive brief

A vulnerability in Schneider Electric PowerLogic P7 protection relays could allow an authorized user to crash the device. These devices are used in electrical power systems to monitor and protect industrial infrastructure. If exploited, the device would become unavailable, potentially disrupting power management operations and requiring a manual restart.

Technical details

A Reachable Assertion (CWE-617) vulnerability exists in the Schneider Electric PowerLogic P7 firmware. An authenticated attacker with high privileges can send a specially crafted request to a network-exposed service, causing the system to hit an internal assertion failure and crash. This results in a denial-of-service (DoS) condition affecting system availability. The vulnerability is present in version V02.003.001.000 and prior. Remediation typically involves updating to a patched firmware version provided by the vendor.

Affected products

  • Schneider Electric PowerLogic P7 V02.003.001.000 and prior

Timeline

  • 2026-06-25: advisory: Initial disclosure by Schneider Electric and NVD publication.

References

Related threats