CVE-2025-8754
CVSS 7.5 HIGH: missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB… EPSS 0.4% (29th percentile).
Vulnerabilities · 111 days ago
The broken control is availability. If an attacker can reach ABB Ability™ zenon on the network, the product’s password gate does not stop them from forcing a reboot on the target system.
CISA says CVE-2025-8754 affects ABB Ability™ zenon versions >=7.50 to <=14. The flaw lets an attacker use the Remote Transport Service’s Reboot OS function without the required authentication, and ABB says remote exploitation is only feasible after the attacker already has network access. ABB reports no active exploitation in the wild.
For critical-infrastructure operators, the practical barrier is network placement, not the missing password check. That keeps this in the availability bucket: a reachable zenon deployment can be disrupted even when credentials are not known.
CVSS 7.5 HIGH: missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB… EPSS 0.4% (29th percentile).
1 source covering this story
ABB Ability Zenon Remote Transport Vulnerability (Update A) | CISA
ABB Ability Zenon Remote Transport Vulnerability (Update A) Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory.
Part of the PlainSec briefing for 2026-05-26