The broken control is availability. If an attacker can reach ABB Ability™ zenon on the network, the product’s password gate does not stop them from forcing a reboot on the target system.
CISA says CVE-2025-8754 affects ABB Ability™ zenon versions >=7.50 to <=14. The flaw lets an attacker use the Remote Transport Service’s Reboot OS function without the required authentication, and ABB says remote exploitation is only feasible after the attacker already has network access. ABB reports no active exploitation in the wild.
For critical-infrastructure operators, the practical barrier is network placement, not the missing password check. That keeps this in the availability bucket: a reachable zenon deployment can be disrupted even when credentials are not known.