Apply vendor-released firmware updates: BMXNOE0100 version 3.60, BMXNOE0110 version 6.80, Modicon M340 Controller SV3.70, BMXNOR0200H SV1.7_IR27. As interim mitigations, disable FTP service when not in use, implement network segmentation, block unauthorized access to port 21/FTP via firewall, and use VPN tunnels for remote access.
Quick answers
What is CVE-2025-6625?
Apply vendor-released firmware updates: BMXNOE0100 version 3.60, BMXNOE0110 version 6.80, Modicon M340 Controller SV3.70, BMXNOR0200H SV1.7_IR27. As interim mitigations, disable FTP service when not in use, implement network segmentation, block unauthorized access to port 21/FTP via firewall, and use VPN tunnels for remote access.
How severe is CVE-2025-6625?
high, CVSS 7.5
Is CVE-2025-6625 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2025-6625 be mitigated?
Apply vendor-released firmware updates: BMXNOE0100 version 3.60, BMXNOE0110 version 6.80, Modicon M340 Controller SV3.70, BMXNOR0200H SV1.7_IR27. As interim mitigations, disable FTP service when not in use, implement network segmentation, block unauthorized access to port 21/FTP via firewall, and use VPN tunnels for remote access.
CVSS
7.5
Vendor
Schneider Electric
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Modicon M340 Ethernet/Serial RTU Module, M580 Global Data module, Ethernet/Serial RTU Module, Modbus/TCP Ethernet Modicon M340 module, Modbus/TCP Ethernet Modicon M340 FactoryCast module, Modicon M340 Controller firmware prior to SV3.70
Mitigation
Apply vendor-released firmware updates: BMXNOE0100 version 3.60, BMXNOE0110 version 6.80, Modicon M340 Controller SV3.70, BMXNOR0200H SV1.7_IR27. As interim mitigations, disable FTP service when not in use, implement network segmentation, block unauthorized access to port 21/FTP via firewall, and use VPN tunnels for remote access.
Schneider Electric has disclosed a vulnerability in its Modicon M340 Controller and Communication Modules tracked as CVE-2025-6625. The issue stems from improper input validation in multiple firmware versions and could allow an unauthenticated attacker to send a crafted FTP command that triggers a Denial of Service condition, rendering affected devices unavailable. The vulnerability has a CVSS v3 base score of 7.5 (High).