Junglewise Threat Intelligence

CVE-2025-7705: ABB Busch-Welcome Door Opener Actuator authentication bypass

CVE-2025-7705 · Severity: high · CVSS 6.8 · Published 2026-05-28

Vendors: ABB.

Executive brief

ABB Busch-Welcome door opener actuators, which are used to control physical access to buildings, contain a vulnerability that could allow unauthorized individuals to bypass security. By exploiting a misconfiguration in the device's operating mode, an attacker with physical access to the hardware could trigger the door to open. This poses a significant risk to the physical security of commercial facilities and residential buildings where these systems are installed.

Technical details

The ABB Busch-Welcome 2 Wire Door Opener Actuator (models 83330 and 83330-500) contains an authentication bypass vulnerability classified as CWE-489 (Active Debug Code). The issue stems from a compatibility mode being enabled by default, which can be exploited by an attacker with physical access to the device. Successful exploitation allows the attacker to bypass intended security controls and actuate the door opening mechanism. ABB has provided a manual remediation procedure involving toggling the physical mode switch between 'Door-Open' and 'Light' modes followed by a power reset to trigger a system recalibration and correct the misconfiguration.

Affected products

  • ABB Busch-Welcome 2 Wire Door Opener Actuator (Switch Actuator 4 DU - 83330) All versions
  • ABB Busch-Welcome 2 Wire Door Opener Actuator (Switch actuator, door/light 4 DU - 83330-500) All versions

Timeline

  • 2025-07-21: advisory: Initial vendor advisory released by ABB
  • 2026-05-28: advisory: CISA republication of the advisory

References