CVE-2025-7746 describes a Cross-site Scripting (XSS) vulnerability (CWE-79) where improper input neutralization allows malicious users to inject unvalidated data, potentially modifying or reading data in a victim's browser. This vulnerability has a CVSS score of 5.3 (MEDIUM), indicating a network-based attack with low complexity requiring user interaction, but with no direct impact on confidentiality, integrity, or availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Schneider Electric | ATS490 Altivar Soft Starter | all versionsCNA affecteddefault unaffected | |
| Schneider Electric | ATV340E Altivar Machine Drives | all versionsCNA affecteddefault unaffected | |
| Schneider Electric | ATV6000 Medium Voltage Altivar Process Drives | all versionsCNA affecteddefault unaffected | |
| Schneider Electric | ATV630/650/660/680/6A0/6B0/6L0 Altivar Process Drives | all versionsCNA affecteddefault unaffected | |
| Schneider Electric | ATV930/950/955/960/980/9A0/9B0/9L0/991/992/993 Altivar Process Drives | all versionsCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.