CVE-2025-3756Active Exploitation

MEDIUMCVSS 7.1 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed as affected in this CVE. An attacker with access to IEC 61850 networks could exploit the vulnera bility by using a specially crafted 61850 packet, forcing the communication interfaces of the PM 877, CI850 and CI868 modules into fault mode or causing unavailability of the S+ Operations 61850 connectivity, resulting in a denial-of-service situation.  The System 800xA IEC61850 Connect is not affected. Note: This vulnerability does not impact on the overall availability and functionality of the S+ Operations node, only the 61850 communication function.     This issue affects AC800M (System 800xA): from 6.0.0x through 6.0.0303.0, from 6.1.0x through 6.1.0031.0, from 6.1.1x through 6.1.1004.0, from 6.1.1x through 6.1.1202.0, from 6.2.0x through 6.2.0006.0; Symphony Plus SD Series: A_0, A_1, A_2.003, A_3.005, A_4.001, B_0.005; Symphony Plus MR (Melody Rack): from 3.10 through 3.52; S+ Operations: 2.1, 2.2, 2.3, 3.3.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1284

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-30: 2Active Exploitation · 2026-04-30: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-30: 204-30
Signal classification2 categories
Active Exploitation
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers are exploiting CVE-2025-3756 in ABB's IEC 61850 communication stack by sending specially crafted packets to industrial control systems. The attack forces critical modules into fault states, disrupting power grid and industrial operations. Network segmentation helps contain such attacks to isolated zones. #CriticalInfrastructure #ICS 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/icsa-26-120-01-cve-2025-3756

    Post summary

    Attackers are actively exploiting CVE-2025-3756 in ABB’s IEC 61850 stack by sending crafted packets that cause critical modules to fault, disrupting operations; no patch or mitigation is mentioned.

    00000616
    1.9K followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 CVE-2025-3756 is a DoS, not a takeover… but in OT that’s basically “your factory’s Wi‑Fi is dead.” Translation: segmentation first beats patch panic. #Windows #Security #OT https://windowsforum.com/threads/cve-2025-3756-iec-61850-dos-in-abb-ot-network-segmentation-first.415934/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #DenialOfService #AbbVulnerabilities #IndustrialControlSecurity #Iec61850Mms https://t.co/HWpIRKdVSb

    Post summary

    The post highlights that CVE-2025-3756 is a DoS flaw in IEC 61850 and stresses using segmentation as a mitigation, but provides no exploit, PoC, or evidence of active attacks.

    00000612
    1.1K followersView on X

Explore more