CVE-2025-14771: File Disclosure in ABB T-MAC Plus web application and in ABB T-MAC plus Server - Default IIS Web Site
Published Jun 3, 2026
·Updated
Files or directories accessible to external parties vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
Affected Software
3 affected components
ABB T-MAC Plus=4.0-24
ABB T-MAC Plus Server=4.0-24
ABB T-MAC Plus=4.0-24
Event History
Jun 3, 2026
CVE Published
via MITRE·09:16 AM
Data Sourced
via MITRE·09:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-14771?
CVE-2025-14771 has a severity rating of critical, with a CVSS score of 9.9.
2
What does CVE-2025-14771 affect?
CVE-2025-14771 affects the ABB T-MAC Plus web application and ABB T-MAC Plus Server versions 4.0-24.
3
What is the risk associated with CVE-2025-14771?
The risk associated with CVE-2025-14771 is rated at a risk level of 82.
4
How do I fix CVE-2025-14771?
To fix CVE-2025-14771, ensure that the latest patches and updates for ABB T-MAC Plus and ABB T-MAC Plus Server are applied.
5
What type of vulnerability is CVE-2025-14771?
CVE-2025-14771 is a file disclosure vulnerability that allows unauthorized access to files or directories.