Impact
The vulnerability is an OS command injection identified by CWE‑78. If an authenticated user with SSH access can interact with the operating‑system console, the system fails to neutralize special shell characters, enabling arbitrary command execution. Attackers can elevate their privileges to root and run administrative functions that the device normally restricts, potentially compromising the entire PowerLogic T300 installation.
Affected Systems
This issue affects Schneider Electric PowerLogic T300 controllers. No specific firmware or software revision numbers are disclosed in the advisory, so all currently deployed units are potentially vulnerable until a vendor patch is applied.
Risk and Exploitability
The CVSS score is 8.7, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated session with SSH enabled; no public exploitation is documented. The exploitation path relies on privileged users and could lead to full root access if successful.
OpenCVE Enrichment