---
id: CVE-2021-22769
title: >-
  A CWE-552: Files or Directories Accessible to External Parties vulnerability
  exists in Easergy T300 with firmware V2.7.1 and older that could expose files
  or directory content when access from an attacker is not restricted or
  incorrectly…
summary: >-
  A CWE-552: Files or Directories Accessible to External Parties vulnerability
  exists in Easergy T300 with firmware V2.7.1 and older that could expose files
  or directory content when access from an attacker is not restricted or
  incorrectly…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-552
vendor: schneider-electric
product: easergy_t300_firmware
affected:
  - easergy_t300_firmware <= 2.7.1
published: '2021-06-11'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-22769'
references:
  - url: 'http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-02'
    label: cybersecurity@se.com
  - url: 'http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-02'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00652
epssPercentile: 0.4898
ingestedAt: '2026-06-29T14:29:18.052Z'
---

## Overview

A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.

## Affected

- `easergy_t300_firmware <= 2.7.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
