CVE-2025-7745
CVSS 5.8 MEDIUM: buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2. EPSS 0.4% (33rd percentile).
Vulnerabilities & Exploits · IoT / OT Attack
ABB’s AC500 V2 Modbus server can leak pieces of older responses into a new reply. That means a failed or unsupported request can still expose prior commands or telemetry, so “it only returned an error” is the wrong conclusion.
CISA says AC500 V2 firmware through 2.5.2 is affected by CVE-2025-7745. Firmware 2.5.3 and later fixes the buffer over-read, and the advisory covers deployments in critical manufacturing, energy, and water and wastewater.
For OT teams, the issue is not just malformed-client noise. Leaked Modbus fragments can reveal how the PLC was behaving before the bad request, which gives an attacker a way to map device activity and process state without full control of the controller.
1 source · May 26
CVSS 5.8 MEDIUM: buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2. EPSS 0.4% (33rd percentile).
CISA Advisories
ABB AC500 V2 | CISA
ABB AC500 V2 Summary ABB became aware of vulnerabilities in AC500 V2 listed as affected in the advisory.
originalPart of the PlainSec briefing for 2026-05-26
Every edition of this story: ABB PLC Bug Leaks Old Modbus Traffic