CVE-2025-9997 is an OS Command Injection vulnerability (CWE-78) in BLMon, allowing attackers to execute arbitrary commands within an SSH session. Rated Medium severity (CVSS 5.8), it requires local access and physical interaction, but can lead to high confidentiality impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Schneider Electric | Saitel DP RTU | >= all versions, <= 11.06.33CNA affecteddefault unaffected | |
| Schneider Electric | Saitel DR RTU | >= all versions, <= 11.06.29CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.