Junglewise Threat Intelligence

CVE-2025-14773: ABB T-MAC Plus cross-site scripting

CVE-2025-14773 · Severity: high · CVSS 8 · Published 2026-06-03

Technologies: ABB T-MAC Plus. Vendors: ABB.

Executive brief

ABB T-MAC Plus, a device used for building automation and energy management, contains a security flaw that could allow an attacker to execute malicious scripts in a user's browser. If a technician or administrator interacts with a malicious link or page while logged into the device, the attacker could steal session information or perform unauthorized actions. This could lead to unauthorized access to building control systems and sensitive configuration data.

Technical details

A reflected or stored cross-site scripting (XSS) vulnerability exists in ABB T-MAC Plus version 4.0-24 due to improper neutralization of input during web page generation. An unauthenticated remote attacker can exploit this by tricking a legitimate user into clicking a specially crafted link or visiting a compromised page. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser session, potentially leading to the theft of session cookies, sensitive information disclosure, or the performance of actions on behalf of the authenticated user. Users are advised to consult ABB's official security advisory for mitigation steps or firmware updates.

Affected products

  • ABB T-MAC Plus 4.0-24

Timeline

  • 2026-06-03: advisory: Vulnerability published by ABB and NVD.

References

Related threats