Executive brief
ABB AWIN GW100 and GW120 wireless gateways, which are used to connect industrial devices to networks, contain a security flaw where critical functions do not require a password. An attacker on the same local network could exploit this to interfere with the device's operations. This could lead to a loss of connectivity or a denial of service for the industrial systems relying on these gateways.
Technical details
A missing authentication vulnerability (CWE-306) exists in the ABB AWIN GW100 rev.2 and GW120 wireless gateways. The flaw allows an unauthenticated attacker with adjacent network access to execute critical functions that should be restricted. According to the CVSS metrics, the primary impact is on availability, suggesting that an attacker could reboot the device, change critical settings, or otherwise disrupt the gateway's service. The vulnerability affects AWIN GW100 rev.2 versions 2.0-0 and 2.0-1, and AWIN GW120 versions 1.2-0 and 1.2-1.
Affected products
- ABB AWIN GW100 rev.2 2.0-0, 2.0-1
- ABB AWIN GW120 1.2-0, 1.2-1
Timeline
- 2026-03-13: disclosed
- 2026-03-13: advisory