← Back to home
ICSA-25-322-02  ·  Published 2025-11-18  ·  View on CISA ICS-CERT ↗

Shelly Pro 4PM

CVSS 7.4 HIGH

Risk Summary

Successful exploitation of this vulnerability could result in a denial-of-service condition.

CVEs (1)

Remediations

  • Shelly did not respond to CISA's attempts at coordination. Users of Shelly Pro 4PM devices are encouraged to contact Shelly and keep their systems up to date, as versions later than 1.6.0 are not vulnerable to the exploit.

Affected Vendors

Shelly

Affected Products (1)

Shelly · Pro 4PM <v1.6

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more