Description
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause privilege escalation to root and unauthorized execution of administrative functions when an authenticated user with SSH enabled interacts with the operating system console that improperly processes user-controlled input.
Published: 2026-09-09
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an OS command injection identified by CWE‑78. If an authenticated user with SSH access can interact with the operating‑system console, the system fails to neutralize special shell characters, enabling arbitrary command execution. Attackers can elevate their privileges to root and run administrative functions that the device normally restricts, potentially compromising the entire PowerLogic T300 installation.

Affected Systems

This issue affects Schneider Electric PowerLogic T300 controllers. No specific firmware or software revision numbers are disclosed in the advisory, so all currently deployed units are potentially vulnerable until a vendor patch is applied.

Risk and Exploitability

The CVSS score is 8.7, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated session with SSH enabled; no public exploitation is documented. The exploitation path relies on privileged users and could lead to full root access if successful.

Generated by OpenCVE AI on September 9, 2026 at 17:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to a fixed version.
  • Disable SSH on the console or restrict SSH access to trusted IP ranges.
  • Enforce strong, least‑privilege credentials for administrative accounts.
  • Monitor system logs for abnormal command execution and validate all console input rigorously.

Generated by OpenCVE AI on September 9, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Command Injection in Schneider Electric PowerLogic T300 Allowing Privilege Escalation

Wed, 09 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause privilege escalation to root and unauthorized execution of administrative functions when an authenticated user with SSH enabled interacts with the operating system console that improperly processes user-controlled input.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2026-09-09T16:31:30.473Z

Reserved: 2026-08-20T12:54:51.607Z

Link: CVE-2026-77120

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T17:17:41.997

Modified: 2026-09-09T17:17:41.997

Link: CVE-2026-77120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T17:30:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')