{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/bmxngd0100/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2025-6625"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Modicon M340 (all versions prior to SV3.70)","BMXNOE0100 (\u003c 3.60)","BMXNOE0110 (\u003c 6.80)","BMXNOR0200H (\u003c SV1.7_IR27)","BMXNGD0100","BMXNOC0401"],"_cs_severities":["low"],"_cs_tags":["ics","cve-2025-6625","denial-of-service","schneider-electric"],"_cs_type":"advisory","_cs_vendors":["Schneider Electric"],"content_html":"\u003cp\u003eSchneider Electric has disclosed a vulnerability (CVE-2025-6625) affecting multiple Modicon M340 controller and communication modules. The flaw stems from improper input validation in the device's FTP service, which is susceptible to denial-of-service (DoS) attacks. An unauthenticated remote attacker can send a specially crafted FTP command to an affected device, causing it to crash or become unresponsive, leading to operational unavailability.\u003c/p\u003e\n\u003cp\u003eThe vulnerability impacts a wide range of modules, including the BMXNOR0200H, BMXNGD0100, BMXNOC0401, BMXNOE0100, and BMXNOE0110, as well as the core M340 controller firmware. Given the deployment of these devices in critical infrastructure sectors like energy, water and wastewater, and manufacturing, the impact of service disruption is significant. Schneider Electric has released firmware updates for several modules and recommends disabling FTP services or implementing strict network segmentation if patching is not immediately feasible.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a Denial of Service (DoS), rendering the affected industrial controller unavailable. This poses a high risk to critical infrastructure sectors - including energy, water, wastewater, and chemical manufacturing - where device uptime is essential for safe operations. There are no reports of remote code execution or data exfiltration associated with this specific vulnerability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the vendor-provided firmware updates immediately to affected modules:\u003c/li\u003e\n\u003cli\u003eUpdate BMXNOE0100 to version 3.60 or later.\u003c/li\u003e\n\u003cli\u003eUpdate BMXNOE0110 to version 6.80 or later.\u003c/li\u003e\n\u003cli\u003eUpdate Modicon M340 controller firmware to version SV3.70 or later.\u003c/li\u003e\n\u003cli\u003eUpdate BMXNOR0200H to version SV1.7 IR27 or later.\u003c/li\u003e\n\u003cli\u003eDisable the FTP service on all Modicon M340 modules if it is not required for operational tasks.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation and firewall rules to block unauthorized access to TCP port 21 on all industrial devices.\u003c/li\u003e\n\u003cli\u003eRequire the use of VPNs for any necessary remote maintenance or monitoring access to the control network.\u003c/li\u003e\n\u003cli\u003eEnsure controllers are kept in locked cabinets and are not left in \u0026quot;Program\u0026quot; mode during standard operation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T17:11:59Z","date_published":"2026-09-17T17:11:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-modicon-m340-dos/","summary":"An improper input validation vulnerability (CVE-2025-6625) in Schneider Electric Modicon M340 controllers and communication modules allows unauthenticated attackers to cause a denial-of-service via crafted FTP commands.","title":"Improper Input Validation in Schneider Electric Modicon M340 Modules","url":"https://feed.craftedsignal.io/briefs/2026-09-modicon-m340-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - BMXNGD0100","version":"https://jsonfeed.org/version/1.1"}