You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2025 9574
About this tag
CVE-2025-9574 is a critical vulnerability affecting ABB ALS-mini load controllers, specifically the ALS-mini-S4 IP and ALS-mini-S8 IP models. The flaw allows unauthenticated remote attackers to read and modify device configuration through the embedded web server, due to a complete lack of authentication on management functions. Devices with serial numbers between 2000 and 5166, across all firmware versions, are impacted. The vulnerability has been scored as critical under both CVSS v3.1 and CVSS v4.0. This tag covers discussions and technical details about CVE-2025-9574, including affected hardware, exploitation vectors, and potential mitigations for industrial control system environments.
A newly disclosed, high-severity vulnerability in ABB’s legacy ALS‑mini load controllers (ALS‑mini‑S4 IP and ALS‑mini‑S8 IP) allows unauthenticated remote attackers to read and change device configuration through the embedded web server — a flaw tracked as CVE‑2025‑9574 and scored critical under...