CVE-2025-13777: Authentication Bypass due to Improper Session Validation
Published Mar 13, 2026
·Updated
Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.
Affected Software
2 affected components
ABB AWIN GW100>=2.0-0<=2.0-1
ABB AWIN GW120>=1.2-0<=1.2-1
Event History
Mar 13, 2026
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:53 PM
DescriptionSeverityWeakness
Dec 1, 58350
Event
via NVD·06:19 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-13777?
CVE-2025-13777 has a high severity rating due to the potential for authentication bypass.
2
How do I fix CVE-2025-13777?
To mitigate CVE-2025-13777, apply the latest firmware updates provided by ABB for AWIN GW100 rev.2 and AWIN GW120.
3
Which versions are affected by CVE-2025-13777?
CVE-2025-13777 affects ABB AWIN GW100 rev.2 versions 2.0-0 to 2.0-1 and AWIN GW120 versions 1.2-0 to 1.2-1.
4
What are the risks associated with CVE-2025-13777?
The primary risk of CVE-2025-13777 is unauthorized access to systems due to improper session validation.
5
How can I verify if my device is vulnerable to CVE-2025-13777?
You can verify the vulnerability by checking the firmware version of your ABB AWIN GW100 rev.2 or AWIN GW120 against the affected versions listed in CVE-2025-13777.