CVE-2025-10571Active Exploitation

LOWCVSS 9.4 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects ABB Ability Edgenius: 3.2.0.0, 3.2.1.1.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-30: 2Active Exploitation · 2026-04-30: 1Technical Details · 2026-04-30: 104-30
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Andre Gironda@AndreGironda
    General

    AV25-776 CVE-2025-10571 ABB Edgenius management portal -- https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-03

    Post summary

    The text references CVE-2025-10571 linked to ABB Edgenius management portal and provides a link to a CISA advisory, but offers no additional details on the vulnerability or its exploitation.

    00010693
    3.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2025-10571 in ABB Ability Edgenius can bypass authentication entirely, then escalate privileges to install arbitrary code and move laterally across networks. This edge platform compromise demonstrates how industrial systems require runtime segmentation to limit blast radius. #ZeroTrust #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/icsa-26-120-03-cve-2025-10571

    Post summary

    The report confirms that attackers are actively using CVE‑2025‑10571 to bypass authentication, gain full control over ABB Ability Edgenius, and move laterally, highlighting a critical need for runtime segmentation in industrial systems.

    00000615
    1.9K followersView on X

Explore more