PatchSiren cyber security CVE debrief
CVE-2025-2441 Schneider Electric CVE debrief
CVE-2025-2441 is a medium-severity Schneider Electric vulnerability affecting Trio™ Q Licensed Data Radio devices prior to firmware version 2.7.2. According to the CISA CSAF advisory, a malicious user with physical access can place the radio into factory default mode, where the product does not correctly initialize all data, creating a risk of confidentiality loss. Schneider Electric provides a fixed firmware release and recommends following the documented update and verification steps.
- Vendor
- Schneider Electric
- Product
- Trio™ Q Licensed Data Radio
- CVSS
- MEDIUM 4.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-08
- Original CVE updated
- 2025-04-08
- Advisory published
- 2025-04-08
- Advisory updated
- 2025-04-08
Who should care
Industrial control system owners and operators using Schneider Electric Trio™ Q Licensed Data Radio devices, especially sites where equipment may be physically accessible to unauthorized personnel. OT security teams, maintenance staff, system integrators, and field technicians should also care because mitigation depends on firmware updating, physical security, and firmware verification.
Technical summary
The advisory describes a CWE-1188 incorrect initialization of resource condition in Schneider Electric Trio™ Q Licensed Data Radio devices. The affected scope is version prior to 2.7.2. The vulnerability is exploitable only with physical access and is associated with factory default mode, where not all data is correctly initialized. The documented impact is loss of confidentiality, and the published CVSS vector is AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (4.6 medium).
Defensive priority
Moderate. Apply the vendor firmware fix promptly if these radios are deployed in accessible environments or handle sensitive data. The issue requires physical access, but the confidentiality impact is high, so devices in fielded or lightly protected locations should be prioritized.
Recommended defensive actions
- Upgrade Trio™ Q Licensed Data Radio firmware to version 2.7.2 or later using Schneider Electric's published update package.
- Follow Section 10 Part J of the Trio Q Series Data Radio User Manual to download, install, and verify the new firmware version.
- Verify installed firmware using the hash published with the release notes before deployment or return to service.
- Restrict physical access to deployed radios and place them in secure locations to reduce the chance of unauthorized interaction.
- Securely dispose of decommissioned radios to prevent unauthorized physical access to equipment and data.
- If immediate patching is not possible, apply the vendor's listed mitigations and document residual risk for affected assets.
Evidence notes
CISA's CSAF advisory ICSA-25-107-01 states that the issue affects Schneider Electric Trio™ Q Licensed Data Radio version prior to 2.7.2 and describes a CWE-1188 incorrect initialization of resource condition that can cause confidentiality loss when a malicious user with physical access sets the radio in factory default mode. The advisory lists CVSS 4.6 with vector CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Schneider Electric's referenced security notice and firmware release materials identify v2.7.2 as the fix and instruct users to follow the manual's firmware update and verification steps. The enrichment provided here indicates the CVE is not in CISA KEV and no ransomware campaign use is known.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-2441 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-2441
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-2441 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-2441
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-107-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/us/en/download/document/7EN52-0390
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-107-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.