← All Advisories

CVE-2026-6865

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-6865

Key Details

CVECVE-2026-6865
CVSS Score / Version7.1 (High) / CVSS v4.0
Updated2026-06-17
Affected productsSchneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller and Schneider Electric Saitel DP Remote Terminal Unit & Controller
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Schneider ElectricEasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller
Schneider ElectricSaitel DP Remote Terminal Unit & Controller
SubsystemsGeneral OT
SectorsMultiple

What to Know

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause unauthorized access to sensitive files when user-supplied input is improperly handled during server-side file path processing.

What to Do

Monitor Schneider Electric's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-6865
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-6865