# ABB Ability zenon Remote Transport Service CVE-2025-8754 — Missing Authentication Allows Unauthorized Remote Reboot of OT Systems

> A Missing Authentication for Critical Function vulnerability (CWE-306) in the ABB Ability zenon software platform allows an unauthenticated network attacker to invoke the Reboot OS function exposed by the zensyssrv.exe Remote Transport Service. CISA published ICSA-26-146-03 on 2026-05-26 confirming all zenon versions from 7.50 through 14 are affected across eight critical infrastructure sectors. CVSS v3.1 7.5 HIGH (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) / CVSS v4.0 8.7 — availability-only impact with no confidentiality or integrity loss, but trivially weaponizable for industrial denial-of-service.

- **Published:** 2026-05-26T00:00:00Z
- **Last reviewed:** 2026-05-26T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0594
- **ID:** TL-2026-0594
- **Severity:** HIGH (CVSS 7.5)
- **Category:** ICS_SCADA
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-8754

## Description

ABB Ability zenon is a widely-deployed HMI/SCADA software platform used to engineer and operate supervisory control systems in Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, and Water and Wastewater sectors worldwide. The platform's runtime is supported by the zensyssrv.exe Windows service (ABB zenon System Service), which by default is set to start automatically and which exposes the Remote Transport Service (RTS). RTS is intended to permit engineering operations to be performed remotely against a zenon Runtime host, and it nominally requires the operator to configure a password before any RTS function can be invoked.

CVE-2025-8754 is an authentication bypass affecting the Reboot OS command exposed by RTS. The vulnerability allows an attacker who can reach the zensyssrv.exe service over the network to invoke the Reboot OS function without supplying the configured RTS password. The advisory text from ABB PSIRT and CISA's ICSA-26-146-03 (released 2026-05-26) describes the flaw as a Missing Authentication for Critical Function (CWE-306), placing it squarely in the same class as the OPC UA / IEC-104 / Modbus historical patterns where ICS-specific protocol handlers either omit credential checks entirely or fail to enforce them on a privileged subset of operations. The CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H reflects a pure availability impact: no data is exfiltrated and no integrity is modified, but the target Windows host can be forcibly rebooted at will by an unauthenticated attacker on the same network.

In an OT context the operational impact is disproportionately severe. zenon Runtime is frequently deployed on stand-alone industrial PCs that drive HMI screens, historian collectors, batch controllers, and gateway nodes to PLCs over IEC 60870-5-104, OPC UA, S7, Modbus TCP, and proprietary fieldbus protocols. An unscheduled reboot during a production run can: (1) lose the in-memory state of an HMI session and detach operator visibility from the process, (2) drop active OPC UA / S7 subscriptions and force a reconnection storm against downstream PLCs, (3) interrupt batch or recipe execution mid-step, (4) lose unwritten historian buffers that have not yet flushed to the SQL backend, and (5) for systems in N+1 redundancy, trigger a forced failover that itself can cascade if the standby is similarly vulnerable. Repeat invocation produces a sustained denial-of-service that prevents the operator from regaining control. In safety-instrumented environments the loss of HMI visibility can force an operator to invoke a process trip out of an abundance of caution, converting an IT-layer DoS into a real physical-process shutdown.

The exploit primitive is straightforward and is the canonical Tier-1 ICS vulnerability shape: a critical action handler that does not verify the caller's authentication state before executing. The zensyssrv.exe RTS listener accepts a Reboot OS message and reaches the OS-level reboot path (most likely InitiateSystemShutdownEx or ExitWindowsEx with SE_SHUTDOWN_NAME privilege already held by the LocalSystem-account service) without consulting whether the connection has presented the RTS password. Note that the vulnerability is in the authentication state machine of the RTS protocol handler, not in the cryptographic algorithm or password storage — even an unconfigured RTS password is not a precondition for exploitation. No public proof-of-concept code has been released as of the advisory date and ABB PSIRT reported the issue to CISA itself, indicating a coordinated disclosure path; CISA noted that as of publication there is no evidence of in-the-wild exploitation.

The remediation guidance from ABB is mitigation-only at the time of writing: (a) restrict network reachability to zenon hosts using firewalls, ACLs, and OT-segmentation patterns from IEC 62443 / NIST SP 800-82; (b) audit whether RTS is operationally required and, if not, stop and disable zensyssrv.exe; (c) where RTS is required, stop zensyssrv.exe after each authorized engineering session and start it on-demand. The advisory does not list a fixed product version, so defenders should treat all 7.50–14 deployments as vulnerable until ABB publishes a patched build. Defenders should hunt for network reachability of TCP listeners on zenon hosts, unexpected Windows event 6008 (unexpected shutdown) / 1074 (shutdown initiated) clustered around zenon process trees, and abrupt loss of OPC UA / IEC-104 sessions from a zenon runtime to its connected PLCs.

## MITRE ATT&CK

- T1595 Active Scanning
- T1590 Gather Victim Network Information
- T1588 Obtain Capabilities
- T1190 Exploit Public-Facing Application
- T1046 Network Service Discovery
- T1007 System Service Discovery
- T1210 Exploitation of Remote Services
- T1529 System Shutdown/Reboot
- T1499 Endpoint Denial of Service
- T1489 Service Stop

## Sources

- [CISA ICS Advisory ICSA-26-146-03 — ABB AbilityTM Zenon Remote Transport Vulnerability](https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-03)
- [ABB PSIRT Cybersecurity Advisory 2NGA002743 — zenon Remote Transport](https://search.abb.com/library/Download.aspx?DocumentID=2NGA002743&LanguageCode=en&DocumentPartId=&Action=Launch)
- [NVD CVE-2025-8754 — Missing Authentication for Critical Function in ABB Ability zenon](https://nvd.nist.gov/vuln/detail/CVE-2025-8754)
- [CWE-306 — Missing Authentication for Critical Function](https://cwe.mitre.org/data/definitions/306.html)
- [MITRE ATT&CK T1529 — System Shutdown/Reboot](https://attack.mitre.org/techniques/T1529/)
- [MITRE ATT&CK for ICS T0816 — Device Restart/Shutdown](https://attack.mitre.org/techniques/T0816/)
- [ABB Ability zenon Product Page](https://www.copadata.com/en/product/zenon-software-platform/)
- [IEC 62443 ICS Security Zone-and-Conduit Reference](https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0594
