Junglewise Threat Intelligence

CVE-2025-14771: ABB T-MAC Plus unauthorized file and directory access

CVE-2025-14771 · Severity: critical · CVSS 9.9 · Published 2026-06-03

Technologies: ABB T-MAC Plus. Vendors: ABB.

Executive brief

ABB T-MAC Plus, a system used for building automation and energy management, contains a vulnerability that allows unauthorized access to internal files and directories. An attacker could exploit this to view sensitive configuration data, modify system settings, or disrupt operations. This could lead to a total loss of confidentiality and control over the affected building management infrastructure.

Technical details

A vulnerability classified as CWE-552 (Files or Directories Accessible to External Parties) exists in ABB T-MAC Plus version 4.0-24. The flaw allows an authenticated user with low privileges to access sensitive files or directories that should be restricted. Because the CVSS vector indicates a 'Scope Change' (S:C), the impact extends beyond the immediate application to the underlying host or connected systems. An attacker can leverage this access to achieve full confidentiality, integrity, and availability impact (C:H/I:H/A:H) over the network without user interaction.

Affected products

  • ABB T-MAC Plus 4.0-24

Timeline

  • 2026-06-03: advisory: Initial disclosure by ABB and NVD publication.

References

Related threats