Junglewise Threat Intelligence

CVE-2025-13779: ABB AWIN GW100 and GW120 missing authentication for critical function

CVE-2025-13779 · Severity: high · CVSS 8.3 · Published 2026-03-13

Technologies: ABB AWIN GW100 rev.2, ABB AWIN GW120. Vendors: ABB.

Executive brief

A security vulnerability exists in ABB AWIN GW100 and GW120 wireless gateways, which are used to connect industrial devices to networks. The flaw allows an unauthorized person on the local network to access critical functions without a password. This could lead to the theft of sensitive industrial data, unauthorized changes to device settings, or a complete shutdown of the gateway, disrupting industrial operations.

Technical details

A missing authentication vulnerability (CWE-306) exists in the ABB AWIN GW100 rev.2 and GW120 wireless gateways. The flaw resides in critical functions that fail to verify the identity of the requester. An attacker with access to the adjacent network (local subnet) can exploit this vulnerability without any prior authentication or user interaction. Successful exploitation allows the attacker to gain high-impact access to data and availability, potentially leading to full device compromise or denial of service. Affected versions include AWIN GW100 rev.2 (2.0-0, 2.0-1) and AWIN GW120 (1.2-0, 1.2-1).

Affected products

  • ABB AWIN GW100 rev.2 2.0-0, 2.0-1
  • ABB AWIN GW120 1.2-0, 1.2-1

Timeline

  • 2026-03-13: advisory: Initial disclosure by ABB and NVD publication.

References

Related threats