# Schneider Modicon M340 modules vulnerable to FTP DoS

Published: 2026-09-17 · Severity: routine · Sectors: energy, manufacturing, infrastructure
Canonical: https://vorant.io/reports/9b8af072-5b94-5eac-b8dd-cae8ee443257/schneider-modicon-m340-modules-vulnerable-to-ftp-dos

> A crafted FTP command can crash Schneider Electric Modicon M340 controllers and communication modules, causing denial of service; patches available.

Schneider Electric, via CISA ICS advisory ICSA-26-260-04, disclosed CVE-2025-6625, an Improper Input Validation (CWE-20) flaw affecting the Modicon M340 controller and several associated communication modules (BMXNOR0200H, BMXNGD0100, BMXNOC0401, BMXNOE0100, BMXNOE0110). A specially crafted FTP command sent to an affected device can trigger a denial of service, rendering the device unavailable. Affected products span multiple firmware/software versions, including all versions of the Ethernet/Serial RTU module and M580 Global Data module, and versions prior to 3.60/6.80/SV3.70 of other listed modules.

These devices are deployed worldwide across critical infrastructure sectors including chemical, commercial facilities, critical manufacturing, energy, and water/wastewater. Schneider Electric has released vendor fixes for most affected products (BMXNOE0100 v3.60, BMXNOE0110 v6.80, Modicon M340 SV3.70, BMXNOR0200H SV1.7 IR27), each requiring a reboot to complete. A remediation plan is still pending for BMXNGD0100, BMXNOC0401, and future versions of Modicon M340 and BMXNOR0200H.

Until patches are applied, Schneider Electric and CISA recommend disabling the FTP service (disabled by default), blocking port 21/FTP via firewall/network segmentation, and using VPNs for any required remote access. No evidence of in-the-wild exploitation is noted in the advisory; this is a vendor-reported vulnerability disclosed responsibly through Schneider Electric's CPCERT.

## Mentioned in this report

- Vulnerabilities: CVE-2025-6625

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-04

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9b8af072-5b94-5eac-b8dd-cae8ee443257/schneider-modicon-m340-modules-vulnerable-to-ftp-dos.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
