Junglewise Threat Intelligence

CVE-2025-8754: ABB Ability zenon missing authentication in Remote Transport Service

CVE-2025-8754 · Severity: high · CVSS 7.5 · Published 2026-05-26

Vendors: ABB.

Executive brief

ABB Ability zenon is a software platform used for industrial automation and control in sectors such as energy, manufacturing, and water management. A vulnerability in its Remote Transport Service allows an unauthorized person on the same network to remotely reboot the system. This could lead to unexpected service interruptions, loss of real-time monitoring, and operational downtime in critical infrastructure environments.

Technical details

A 'Missing Authentication for Critical Function' vulnerability (CWE-306) exists in the ABB zenon Remote Transport Service (zensyssrv.exe). While the service typically requires a pre-configured password, a flaw allows an unauthenticated attacker with network access to the system to bypass these checks and invoke the 'Reboot OS' function. This is a network-based attack that requires no user interaction or prior privileges. Successful exploitation results in a complete loss of availability for the target machine. ABB recommends restricting network access or disabling the zensyssrv.exe service if remote transport functionality is not required.

Affected products

  • ABB Ability zenon 7.50 to 14

Timeline

  • 2025-08-12: advisory: Initial ABB PSIRT advisory release
  • 2026-05-26: advisory: CISA republication of advisory ICSA-26-146-03

References