All stories
criticalExploited VulnerabilitiesCVE-2025-14771CVE-2025-14772CVE-2025-14773CVE-2025-14774

Critical flaws in ABB T-MAC Plus enable unauthorized file access and authorization bypass

ABB's T-MAC Plus software contains several critical flaws that could allow attackers to access sensitive files or bypass authorization entirely. These vulnerabilities affect versions 4.0 through 24. Immediate updates are necessary for any environments running this product.

Summary

Multiple high and critical severity vulnerabilities have been identified in the ABB T-MAC Plus system. The flaws include a critical issue allowing external parties to access specific files or directories, alongside several authorization bypass vulnerabilities that could permit unauthorized actions within the software.

The affected versions are all within the 4.0 to 24 range. While these vulnerabilities present significant risks to system integrity and confidentiality, they are not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Technical details

The vulnerability landscape for T-MAC Plus involves several distinct attack vectors:

  • CVE-2025-14771 (CVSS 9.9): A critical flaw where files or directories are accessible to external parties. This allows unauthorized access to potentially sensitive system data.
  • CVE-2025-14772 (CVSS 8.8): An authorization bypass vulnerability triggered through a user-controlled key, which could allow an attacker to circumvent established security boundaries.
  • CVE-2025-14773 (CVSS 8.0): A cross-site scripting (XSS) vulnerability caused by improper neutralization of input during web page generation. This requires user interaction to execute.
  • CVE-2025-14774 (CVSS 7.4): An incorrect authorization flaw that could allow unauthorized access or actions within the system.

Proof of Concept

A technical document containing raw data related to these vulnerabilities is available at https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A7840&LanguageCode=en&DocumentPartId=&Action=Launch.

Why this matters for defenders

The presence of a CVSS 9.9 vulnerability indicates that an attacker could potentially gain access to sensitive files without requiring high-level privileges. In industrial environments, unauthorized file access can lead to the exposure of configuration data or proprietary logic.

Furthermore, the combination of authorization bypass and cross-site scripting vulnerabilities means that even if a user is logged in, their session or permissions could be manipulated by an attacker. This creates multiple paths for lateral movement or privilege escalation within the T-MAC Plus environment.

Defender guidance

Identify all instances of ABB T-MAC Plus version 4.0 through 24 within your network. Prioritize patching these systems immediately to mitigate the risk of unauthorized file access and authorization bypass.

If immediate patching is not possible, restrict network access to the T-MAC Plus interface to only trusted, known IP addresses to reduce the attack surface for external parties attempting to exploit the file access vulnerability.

Sources

  1. https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03
  2. https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A7840&LanguageCode=en&DocumentPartId=&Action=Launch
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -