CVE-2025-14772: Broken Access Control in ABB T-MAC Plus web application
Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Until a vendor fix is available and applied, restrict network access to the T-MAC Plus web interface (management UI) to trusted management IPs/networks only (firewall/ACL/VPN/segmentation) and isolate affected devices from untrusted networks.
- Operational
Inventory and identify any ABB T-MAC Plus installations and determine whether they are running version 4.0-24 (the affected version).
- Operational
Contact ABB support or your vendor representative to report the authorization bypass issue and obtain guidance, patches or firmware updates; apply vendor-provided fixes as soon as they are available and monitor vendor advisories for a confirmed fixed version.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14772?
The severity of CVE-2025-14772 is rated as high with a score of 8.8.
What type of vulnerability is CVE-2025-14772?
CVE-2025-14772 is classified as a Broken Access Control vulnerability.
How do I fix CVE-2025-14772?
To fix CVE-2025-14772, ensure proper authorization checks are implemented in the ABB T-MAC Plus web application.
What software is affected by CVE-2025-14772?
CVE-2025-14772 affects the ABB T-MAC Plus versions 4.0 to 24.
What are the potential impacts of CVE-2025-14772?
CVE-2025-14772 can lead to unauthorized access and control over sensitive functions in the ABB T-MAC Plus web application.