Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-1058 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

CWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when malicious firmware is downloaded.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-494Download of Code Without Integrity Check[email protected]

Affected Products

ProductVersions
Schneider Electric ASCO 5310
<= 0

CPE

  • cpe:2.3:h:schneider-electric:asco_5310:*:*:*:*:*:*:*:*

Remediation

  • Mitigation:low effort

    Use the ASCO 5310 only in a protected environment to minimize network exposure and ensure that it is not accessible from the public internet or untrusted networks.

  • Mitigation:low effort

    Change the default password to help prevent unauthorized access to device settings and information.

  • Mitigation:low effort

    Set up network segmentation and implement a firewall to block all unauthorized access to the ASCO 5310 port 80/HTTP.

  • Reference:low efforthttps://www.se.com/ww/en/product-range/66129-asco-5310-singlechannel-remote-annunciator/#documents
Schneider Electric ASCO 5350
<= 0

CPE

  • cpe:2.3:h:schneider-electric:asco_5350:*:*:*:*:*:*:*:*

Remediation

  • Mitigation:low effort

    Use the ASCO 5350 only in a protected environment to minimize network exposure and ensure that it is not accessible from the public internet or untrusted networks.

  • Mitigation:low effort

    Change the default password to help prevent unauthorized access to device settings and information.

  • Mitigation:low effort

    Set up network segmentation and implement a firewall to block all unauthorized access to the ASCO 5350 port 80/HTTP.

  • Reference:low efforthttps://www.se.com/ww/en/product-range/66130-asco-5350-eight-channel-remote-annunciator/#documents

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-1058
NVD Published Date:
Feb 13, 2025
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2025-1058 Details - Not Deferred