highOther

Schneider Electric Modicon M340 Controller and Communication Modules - FTP Denial of Service Vulnerability (CVE-2025-6625)

First seen Sep 20, 2026 · Updated Sep 20, 2026 · CVSS 7.5

ICSOTSCADASchneider-ElectricModicondenial-of-serviceimproper-input-validationcritical-infrastructure

A high-severity Improper Input Validation vulnerability (CVE-2025-6625) affects Schneider Electric Modicon M340 controllers and several associated Ethernet/Serial communication modules. A specially crafted FTP command sent to an affected device can trigger a Denial of Service, potentially rendering the controller or communication module unavailable. This impacts critical infrastructure sectors including energy, water/wastewater, chemical, and critical manufacturing worldwide.

Technical Analysis

CVE-2025-6625 is a CWE-20 Improper Input Validation flaw in the FTP service of Modicon M340 firmware (versions prior to SV3.70) and related communication modules (BMXNOE0100 <3.60, BMXNOE0110 <6.80, BMXNOR0200H <SV1.7_IR27, and all versions of BMXNGD0100 and generic Ethernet/Serial RTU modules). An unauthenticated remote attacker can send a malformed FTP command to the device's exposed FTP port (21), causing a Denial of Service condition (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) with no impact to confidentiality or integrity but full impact to availability. This is a pure OT/ICS availability threat with no direct code-execution or data-exfiltration vector; there is no plausible direct impact to AI agent systems, as the vulnerability is confined to industrial PLC firmware and network modules rather than IT infrastructure, APIs, or software supply chains that agent frameworks depend on.

Affected Systems

Schneider Electric Modicon M340 Controller firmware versions prior to SV3.70; BMXNOE0100 Modbus/TCP Ethernet module versions prior to 3.60; BMXNOE0110 Modbus/TCP Ethernet FactoryCast module versions prior to 6.80; BMXNOR0200H Ethernet/Serial RTU Module versions prior to SV1.7_IR27; BMXNGD0100 M580 Global Data module (all versions, no fix yet); Modicon M340 X80 Ethernet Communication Modules / BMXNOC0401 (all versions, no fix yet)

Indicators of Compromise

  • N/A - No specific indicators of compromise published; exploitation involves crafted FTP protocol commands sent to device port 21/FTP

Remediation Steps

  1. 1

    Update BMXNOE0100 firmware

    Upgrade to version 3.60 or later and reboot the module to complete the firmware upgrade.

  2. 2

    Update BMXNOE0110 firmware

    Upgrade to version 6.80 or later and reboot the module to complete the firmware upgrade.

  3. 3

    Update Modicon M340 controller firmware

    Upgrade to version SV3.70 or later, available via Schneider Electric's product download page.

  4. 4

    Update BMXNOR0200H firmware

    Upgrade to version SV1.7_IR27 or later.

  5. 5

    Disable FTP service

    FTP is disabled by default; ensure it remains disabled when not actively required on all affected modules, especially BMXNGD0100 and BMXNOC0401/M340 X80 modules which currently have no available fix.

  6. 6

    Network segmentation

    Implement firewall rules to block unauthorized access to port 21/FTP and isolate ICS/OT networks from business and internet-facing networks.

  7. 7

    Use secure remote access

    Require VPN tunnels for any remote access to control system networks, keeping VPN software patched and up to date.

CVE / Advisory IDs

CVE-2025-6625

Industries Most Exposed

ChemicalCommercial FacilitiesCritical ManufacturingEnergyWater and Wastewater

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.