Junglewise Threat Intelligence

CVE-2025-10571: ABB Edgenius Management Portal

CVE-2025-10571 · Severity: high · CVSS 9.6 · Published 2026-04-30

Vendors: ABB.

Executive brief

ABB Edgenius Management Portal, a tool used for managing industrial edge computing nodes, contains a critical security flaw. An attacker with access to the local network can bypass security checks to take full control of the system. This allows them to install malicious software, delete existing applications, or change system settings, potentially disrupting manufacturing operations or compromising industrial data.

Technical details

An authentication bypass vulnerability (CWE-288) exists in the ABB Edgenius Management Portal versions 3.2.0.0 and 3.2.1.1. The flaw allows an attacker to bypass security controls by sending specially crafted messages to the system node via an alternate path or channel. Successful exploitation requires the attacker to have network access to the environment where Edgenius is deployed while the portal is running. An attacker can achieve remote code execution (RCE), uninstall applications, and modify configurations. ABB has released a fix in Edgenius version 3.2.2.0 and recommends disabling the portal as a temporary mitigation if the update cannot be applied immediately.

Affected products

  • ABB Edgenius Management Portal 3.2.0.0, 3.2.1.1

Timeline

  • 2026-04-30: advisory: CISA and ABB published the advisory.
  • 2026-04-30: patched: Fixed in version 3.2.2.0.

References