CVE-2025-13957Disclosure

LOWCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-19)
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-10: 1Mentions · 2026-03-18: 1Mentions · 2026-03-19: 3Active Exploitation · 2026-03-18: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 303-1003-1803-19
Signal classification2 categories
Disclosure
480.0%
Active Exploitation
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-181
Active Exploitation1
2026-03-193
Disclosure3
Full discourse5 posts
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Schneider Electric EcoStruxure Data Center Expert Hard-coded Password Remote Code Execution Vulnerability (CVE-2025-13957) #CVE202513957 #CyberSecurity #RemoteCodeExecutionVulnerability #SchneiderElectric https://www.systemtek.co.uk/?p=48797 https://t.co/JETqGNFGqh

    Post summary

    The tweet highlights a remote code execution flaw (hard‑coded password) in Schneider Electric EcoStruxure Data Center Expert (CVE‑2025‑13957) and links to an article for further details.

    00000112
    1.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-13957 CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and adminis… https://www.cve.org/CVERecord?id=CVE-2025-13957 ----- Traducción: CVE-2025-13957 CWE… http://infoflow.cloud`

    Post summary

    A new CVE (CVE‑2025‑13957) describing a hard‑coded credentials flaw that can lead to information disclosure and remote code execution when a SOCKS Proxy is enabled is announced, with no exploit or patch details provided.

    0000086
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13957 CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and adminis… https://www.cve.org/CVERecord?id=CVE-2025-13957

    Post summary

    The tweet announces CVE‑2025‑13957, describing hard‑coded credentials that could lead to information disclosure and RCE when a SOCKS Proxy is enabled, but provides no further technical details, PoC, exploit, or mitigation.

    00000212
    56.8K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting hard-coded credentials in Schneider Electric's EcoStruxure Data Center Expert (CVE-2025-13957) to escalate privileges and move laterally within industrial networks. Runtime segmentation helps limit blast radius when management systems are compromised. #ZeroTrust 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/schneider-electric-2026-hardcoded-credentials-vulnerability

    Post summary

    Attackers are actively exploiting hard‑coded credentials in Schneider Electric's EcoStruxure Data Center Expert (CVE‑2025‑13957) to achieve privilege escalation and lateral movement within industrial networks.

    00000128
    1.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-13957 - PostgreSQL SOCKS Proxy Hard-coded Credentials Remote Code Execution Intel Report: https://ift.tt/xkXYzCy

    Post summary

    The tweet alerts about CVE-2025-13957, highlighting hard‑coded credentials that enable remote code execution in PostgreSQL’s SOCKS Proxy, and links to an intel report, but does not discuss PoCs, active exploitation, or patches.

    0000098
    345 followersView on X

Explore more