Executive brief
ABB WebPro SNMP cards, which are used to monitor and manage Uninterruptible Power Supply (UPS) systems, contain multiple security flaws. An attacker on the same local network could bypass security controls to gain unauthorized access to the device management interface or cause the device to become unresponsive. This could lead to a loss of monitoring capabilities or unauthorized changes to power management settings, potentially impacting critical infrastructure operations.
Technical details
The ABB WebPro SNMP Card PowerValue contains three distinct vulnerabilities. CVE-2025-4676 is an authentication bypass in the web HMI caused by an incorrect implementation where only the first character of session cookies and tokens are validated, allowing for trivial brute-force attacks. CVE-2025-4675 involves an improper implementation of the Modbus protocol on port 502, where unusual conditions can cause the service to become unstable and require a manual reboot. CVE-2025-4677 is a resource exhaustion issue where the lack of idle session timeouts on ports 23 and 502 allows an attacker to exhaust available connections, leading to a denial-of-service. These vulnerabilities are reachable via the local network (Adjacent) and have been addressed in firmware version 1.1.8.p.
Affected products
- ABB WebPro SNMP Card PowerValue <=1.1.8.k, 1.1.8.p
CVE identifiers
- CVE-2025-4675
- CVE-2025-4677
- CVE-2025-4676
Timeline
- 2026-05-12: advisory: CISA ICSA-26-132-06 published
- 2026-05-12: patched: Firmware version 1.1.8.p released