Stack-based Buffer Overflow in ABB RMC-100 and RMC-100 LITE
CVE-2025-6072

8.2HIGH

Key Information:

Vendor

Abb

Vendor
CVE Published:
3 July 2025

What is CVE-2025-6072?

A stack-based buffer overflow vulnerability exists in ABB's RMC-100 and RMC-100 LITE products. When the REST interface is enabled, an attacker on the control network can exploit this flaw by injecting specially crafted JSON configuration data. This exploitation allows the attacker to overflow the date of expiration field, potentially compromising the integrity and functionality of the affected devices. The vulnerability specifically impacts RMC-100 units from versions 2105457-043 to 2105457-045 and RMC-100 LITE units from versions 2106229-015 to 2106229-016.

Affected Version(s)

RMC-100 2105457-043 <= 2105457-045

RMC-100 LITE 2106229-015 <= 2106229-016

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABB thanks Claroty Team82 Research for helping to identify the vulnerabilities and protecting our customers
.
CVE-2025-6072 : Stack-based Buffer Overflow in ABB RMC-100 and RMC-100 LITE