cbcvebase.
CVE-2025-53187
published 2025-08-11

CVE-2025-53187: Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to…

PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.59%
44.8th percentile
Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability may allow an attacker to change the system time, access files, and make function calls without prior authentication. This issue affects all versions of ASPECT prior to 3.08.04-s01

Affected

1 ranges
VendorProductVersion rangeFixed in
abbaspect< <3.08.04-s01<3.08.04-s01

Detection & IOCsextracted from sources · hover to see the quote

  • Authentication bypass via debug code left in production firmware — monitor for unauthenticated requests that successfully change system time, access files, or invoke function calls on ABB ASPECT/NEXUS/MATRIX devices running firmware prior to 3.08.04-s01
  • Network-exploitable, no credentials required (PR:N, UI:N) — alert on anomalous unauthenticated HTTP/S sessions to ABB ASPECT BMS/BAS management interfaces from external or untrusted network segments
  • Affected product families to fingerprint in network inventory: ABB ASPECT-Enterprise ASP-ENT-x, NEXUS Series NEX-2x, NEXUS Series NEXUS-3-x, MATRIX Series MAT-x — all versions prior to 3.08.04-s01 are vulnerable
  • ·Vulnerability is only exploitable if the ASPECT device is reachable from the attacker's network segment — exposure is eliminated if the device is not directly internet-facing and is placed behind a properly configured firewall/VPN
  • ·CVE-2025-53187 is fully remediated only in firmware version 3.08.04-s01 and later; all prior versions of ASPECT firmware remain vulnerable
  • ·Default credentials increase risk — if credentials were not changed during commissioning, the authentication bypass combined with unchanged defaults significantly widens the attack surface

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.