ABB’s AC500 V2 Modbus server can leak pieces of older responses into a new reply. That means a failed or unsupported request can still expose prior commands or telemetry, so “it only returned an error” is the wrong conclusion.
CISA says AC500 V2 firmware through 2.5.2 is affected by CVE-2025-7745. Firmware 2.5.3 and later fixes the buffer over-read, and the advisory covers deployments in critical manufacturing, energy, and water and wastewater.
For OT teams, the issue is not just malformed-client noise. Leaked Modbus fragments can reveal how the PLC was behaving before the bad request, which gives an attacker a way to map device activity and process state without full control of the controller.