Junglewise Threat Intelligence

CVE-2025-3465: ABB CoreSense HM and M10 path traversal

CVE-2025-3465 · Severity: high · CVSS 7.1 · Published 2026-05-19

Vendors: ABB.

Executive brief

ABB CoreSense HM and M10 are monitoring devices used in critical infrastructure sectors like manufacturing and agriculture. A security flaw allows unauthenticated users with local access to bypass directory restrictions and view sensitive system files. This could lead to the exposure of confidential information or a complete compromise of the monitoring system.

Technical details

A path traversal vulnerability (CWE-22) exists in ABB CoreSense HM and CoreSense M10 due to improper validation of the 'file' parameter. While the vulnerability is unauthenticated, it requires local access to the machine hosting the web application (localhost) or access through a compromised local network. An attacker can exploit this to read files outside of the intended directory, potentially leading to full system compromise or sensitive data exposure. The vendor has released updates (CoreSense HM v2.3.4 and CoreSense M10 v1.4.1.31) which implement strict input validation and path sanitization.

Affected products

  • ABB CoreSense HM <=2.3.1, 2.3.4
  • ABB CoreSense M10 <=1.4.1.12, 1.4.1.31

Timeline

  • 2026-05-19: advisory: CISA published advisory ICSA-26-139-01
  • 2026-05-19: patched: Vendor released fixed versions CoreSense HM v2.3.4 and CoreSense M10 v1.4.1.31

References