Junglewise Threat Intelligence

CVE-2025-14772: ABB T-MAC Plus authorization bypass via user-controlled key

CVE-2025-14772 · Severity: high · CVSS 8.8 · Published 2026-06-03

Technologies: ABB T-MAC Plus. Vendors: ABB.

Executive brief

ABB T-MAC Plus, a device used for building automation and energy management, contains a security flaw that allows unauthorized users to bypass access controls. By manipulating specific data keys, an attacker could gain unauthorized access to the system's management functions. This could lead to the disruption of building operations, unauthorized changes to energy settings, or the theft of sensitive configuration data.

Technical details

An authorization bypass vulnerability exists in ABB T-MAC Plus version 4.0-24 due to improper handling of user-controlled keys. An unauthenticated attacker with network access can exploit this by providing a crafted key or identifier that the application uses to make authorization decisions without sufficient validation. Successful exploitation allows the attacker to bypass security checks and perform actions with elevated privileges. This can result in a complete loss of confidentiality, integrity, and availability for the affected device. Users are advised to consult ABB's official security advisory for mitigation steps and firmware updates.

Affected products

  • ABB T-MAC Plus 4.0-24

Timeline

  • 2026-06-03: advisory: Vulnerability published by NVD

References

Related threats