Junglewise Threat Intelligence

CVE-2025-41659: ABB AC500 V3 Multiple Vulnerabilities in PLC Firmware

CVE-2025-41659 · Severity: high · CVSS 8.3 · Published 2026-05-12

Vendors: ABB.

Executive brief

ABB AC500 V3 programmable logic controllers (PLCs), used widely in critical infrastructure like energy and manufacturing, are affected by multiple security flaws. These vulnerabilities could allow an attacker to crash the controller, bypass security logins to view interface files, or gain unauthorized access to digital certificates and encryption keys. Exploitation could lead to operational downtime or the compromise of secure communications within the industrial network.

Technical details

ABB AC500 V3 firmware versions prior to 3.9.0 contain three distinct vulnerabilities. CVE-2025-2595 is a forced browsing flaw (CWE-425) allowing unauthenticated remote attackers to bypass user management and access static visualization files. CVE-2025-41659 involves incorrect permission assignment (CWE-732) in the CmpOpenSSL component, allowing low-privileged users to read or write PKI certificates and keys via the CODESYS protocol. CVE-2025-41691 is a NULL pointer dereference (CWE-476) in the CmpDevice component that allows unauthenticated attackers to trigger a denial-of-service (DoS) state through specially crafted communication requests. These issues are resolved in firmware version 3.9.0.

Affected products

  • ABB AC500 V3 PLC firmware < 3.9.0

CVE identifiers

  • CVE-2025-41659
  • CVE-2025-41691
  • CVE-2025-2595

Timeline

  • 2026-05-12: advisory: CISA ICSA-26-132-03 published
  • 2026-05-12: patched: Firmware version 3.9.0 released

References