Vulnerability Details CVE-2026-2400
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 13.6%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2026-2400
-
cpe:2.3:a:schneider-electric:powerchute_serial_shutdown:1.4