Executive brief
ABB AWIN gateways, which are used to connect industrial wireless sensor networks to plant-level systems, are vulnerable to an authentication bypass. An attacker with access to the local network could capture legitimate communication and replay it to gain unauthorized access to the device. This could allow an attacker to disrupt industrial monitoring operations or access sensitive operational data.
Technical details
A capture-replay vulnerability (CWE-294) exists in the authentication mechanism of ABB AWIN GW100 rev.2 and GW120 gateways. The flaw allows an attacker on the adjacent network to intercept valid authentication traffic and replay it to the device to bypass security controls without knowing the actual credentials. Successful exploitation grants the attacker unauthorized access to the gateway's management or data functions. The vulnerability is confirmed in AWIN GW100 rev.2 versions 2.0-0 and 2.0-1, and AWIN GW120 versions 1.2-0 and 1.2-1. Users are advised to consult ABB advisory 4JNO000329 for remediation steps.
Affected products
- ABB AWIN GW100 rev.2 2.0-0, 2.0-1
- ABB AWIN GW120 1.2-0, 1.2-1
CVE identifiers
- CVE-2025-13778
- CVE-2025-13777
- CVE-2025-13779
Timeline
- 2026-03-13: disclosed: Initial disclosure by ABB
- 2026-03-13: advisory: NVD publication date