Schneider ElectricCVE-2026-77120
Schneider Electric PowerLogic T300: command injection
High8.7CVE-2026-77120 · Published Sep 9, 2026
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause privilege escalation to root and unauthorized execution of administrative functions when an authenticated user with SSH enabled interacts with the operating system console that improperly processes user-controlled input.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| PowerLogic T300 Product | <= Versions 2.9.8-5620 and prior | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Schneider Electric advisories
All Schneider Electric| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 11 | Schneider Electric SCADAPack: weakly protected credentials | Medium5.9 | No fix yet |
| Sep 11 | CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability... | Critical9.2 | No fix yet |
| Sep 9 | Schneider Electric EcoStruxure IT: argument injection | High8.6 | No fix yet |
| Sep 9 | Schneider Electric EcoStruxure IT: server-side request forgery | High8.6 | No fix yet |
| Sep 1 | Schneider Electric NetBotz 5 - 750/755: command injection | High7.3 | No fix yet |
| Sep 1 | Schneider Electric NetBotz 5 - 750/755: SQL injection | Medium5.1 | No fix yet |