Executive brief
ABB T-MAC Plus, a device used for monitoring and controlling building automation systems, contains a security flaw in how it verifies user permissions. An attacker could exploit this weakness to gain unauthorized access to the system's management functions. This could lead to unauthorized changes in building operations, potential data exposure, or disruption of automated services.
Technical details
An incorrect authorization vulnerability exists in ABB T-MAC Plus version 4.0-24. The flaw resides in the access control mechanism, where the application fails to properly validate the permissions of a user or request before granting access to sensitive resources or administrative functions. A remote, unauthenticated attacker can exploit this over the network to bypass security restrictions. Successful exploitation could allow the attacker to view sensitive information, modify configurations, or impact the availability of the device. Users are advised to consult ABB's official security advisories for mitigation steps or firmware updates.
Affected products
- ABB T-MAC Plus 4.0-24
Timeline
- 2026-06-03: advisory: Initial disclosure of CVE-2025-14774