Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ABB — Vulnerabilities & Security Advisories 219

Browse all 219 CVE security advisories affecting ABB. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ABB operates as a global leader in electrification and industrial automation, providing critical infrastructure for power grids, manufacturing, and transportation. With 211 recorded Common Vulnerabilities and Exposures (CVEs), the company’s software and hardware ecosystems have historically been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from legacy industrial control systems and web-based management interfaces, exposing operational technology to potential compromise. Notable incidents include the discovery of hardcoded credentials and unpatched firmware in various PLCs and HMIs, which attackers have exploited to gain unauthorized network access. The sheer volume of CVEs highlights significant challenges in maintaining security across diverse, long-lifecycle products. While ABB implements security updates, the complexity of its integrated solutions continues to present persistent risks for industrial environments relying on its technology.

CVE ID Title CVSS Severity Published
CVE-2026-12705 Integrity mechanism of KNX-device FW-files can be bypassed in ABB Update Tool — KNX Update Tool (ABB) CWE-353 6.4 Medium 2026-07-17
CVE-2025-13162 Advant Master Online Builder DLL vulnerability — Control Builder A CWE-427 4.4 Medium 2026-06-23
CVE-2025-7064 Freelance Security Lock – Access to Windows OS — Freelance CWE-305 6.6 Medium 2026-06-11
CVE-2025-14774 Communication analysis between the Card Reader and TP2CardReaderService daemon — T-MAC Plus CWE-863 7.4 High 2026-06-03
CVE-2025-14773 Stored Cross-Site Scripting in ABB T-MAC Plus web application — T-MAC Plus CWE-79 8.0 High 2026-06-03
CVE-2025-14772 Broken Access Control in ABB T-MAC Plus web application — T-MAC Plus CWE-639 8.8 High 2026-06-03
CVE-2025-14771 File Disclosure in ABB T-MAC Plus web application and in ABB T-MAC plus Server - Default IIS Web Site — T-MAC Plus CWE-552 9.9 Critical 2026-06-03
CVE-2025-3756 Denial of Service Vulnerabilities in System 800xA, Symphony® Plus IEC 61850 — AC800M (System 800xA) CWE-1284 6.5 Medium 2026-04-13
CVE-2025-13779 Configuration Data Spill — AWIN GW100 rev.2 CWE-306 8.3 High 2026-03-13
CVE-2025-13778 Device Reboot Control — AWIN GW100 rev.2 CWE-306 6.5 Medium 2026-03-13
CVE-2025-13777 Authentication Bypass due to Improper Session Validation — AWIN GW100 rev.2 CWE-294 8.3 High 2026-03-13
CVE-2025-14510 ABB Ability OPTIMAX Authentication Bypass in Single-Sign On — ABB Ability OPTIMAX CWE-303 8.1 High 2026-01-16
CVE-2025-4677 Idle session timeout is not configured for multiple open ports — WebPro SNMP Card PowerValue CWE-613 6.5 Medium 2026-01-07
CVE-2025-4676 Authentication bypass by brute forcing Authentication Headers — WebPro SNMP Card PowerValue CWE-303 8.8 High 2026-01-07
CVE-2025-4675 Improper implementation of Modbus protocol leading to DOS attack — WebPro SNMP Card PowerValue CWE-754 6.5 Medium 2026-01-07
CVE-2025-12143 Stack Memory Corruption Vulnerability — Terra AC wallbox CWE-121 6.1 Medium 2025-11-28
CVE-2025-10571 ABB Ability Edgenius Authentication Bypass — ABB Ability Edgenius CWE-288 9.6 Critical 2025-11-20
CVE-2025-12142 BSS(Block Started by Symbol) Memory Corruption Vulnerability — Terra AC wallbox CWE-120 6.1 Medium 2025-10-29
CVE-2025-5517 Heap Memory Corruption Vulnerability — Terra AC wallbox (UL40/80A) CWE-122 6.8 Medium 2025-10-20
CVE-2025-3465 Path Traversal Vulnerability — CoreSense™ HM CWE-22 7.1 High 2025-10-20
CVE-2025-9574 Missing Authentication Vulnerability — ALS-mini-s4 IP CWE-306 10.0 Critical 2025-10-20
CVE-2025-9970 Application credential stored in clear text in memory — MConfig CWE-316 7.4 High 2025-10-08
CVE-2021-22291 EIBPORT Reflected XSS — EIBPORT V3 KNX CWE-79 8.0 High 2025-10-07
CVE-2025-10504 Heap Memory Corruption Vulnerability — Terra AC wallbox CWE-122 6.1 Medium 2025-09-29
CVE-2025-10207 Authenticated File Disclosure/Delete — FLXEON CWE-1287 7.2 High 2025-09-18
CVE-2024-48851 Remote Code Execution — FLXEON CWE-1287 7.2 High 2025-09-18
CVE-2025-10205 Predictable Salt and Weak Hashing Algorithm — FLXEON CWE-759 8.8 High 2025-09-17
CVE-2024-48842 Hardcoded passwords — FLXEON CWE-798 7.0 High 2025-09-17
CVE-2025-8754 ABB AbilityTM zenon Remote Transport Vulnerability — ABB AbilityTM zenon CWE-306 7.5 High 2025-08-13
CVE-2025-7679 Session ID Basic Auth Bypass — Aspect CWE-306 8.1 High 2025-08-11

This page lists every published CVE security advisory associated with ABB. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.