Modicon M241, M251, M258, LMC058 Security Notification (CVE-2025-2875)
This document details a high-severity vulnerability (CVE-2025-2875) in Schneider Electric Modicon M241, M251, M258, and LMC058 programmable logic controllers, which could allow an unauthenticated attacker to read arbitrary files via webserver URL manipulation. It provides remediation steps, including firmware updates to versions v5.3.12.48 (M241/M251) and v5.0.4.19 (M258/LMC058), as well as mitigations such as network segmentation and webserver deactivation.
Failed to load PDF
Download insteadYou might also like
Zelio Time RE7PE11BU Timing Relay Datasheet
2 pages
SP-I01 Single Zone Input Expander Manual
3 pages
Andover Continuum Infinet II i2865-V, i2866-V, i2885-V VAV Box Controllers with Built-in Actuator
6 pages
AP8958EU3 Switched Rack PDU Specifications
18 pages
Satchwell MMC 3701 P+I+D Controller Specification and Application Guide
4 pages
Eurotherm Data Reviewer Log4shell Mitigation Instructions
4 pages
ION Enterprise Energy Monitoring for Industrial Buildings Application Guide
1 pages
SDC 30-4 Series Electric Strike Manual
1 pages
Geo SCADA Expert 2021 Release Notes – July 2022 Update
53 pages
BAS 2800+ Animated Active Graphics Software Specification
4 pages