CVE-2025-1960 - CVE House
Back to Database
Status published Critical CVE-2025-1960

CWE-1188: Initialization of a Resource with an Insecure Default vulnerability...

Vulnerability Description

CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to execute unauthorized commands when a system’s default password credentials have not been changed on first use. The default username is not displayed correctly in the WebHMI interface.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1960

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Schneider Electric

View all reports →

Affected Software

WebHMI – Deployed with EcoStruxure Power Automation System
Vulnerable Versions:
WebHMI v4.1.0.0 and prior when deployed with EPAS User Interface 2.6.30.19 and prior

Timeline

Official Publish: March 12th, 2025
Last Modified: March 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.