CVE-2025-14773: Stored Cross-Site Scripting in ABB T-MAC Plus web application
Published Jun 3, 2026
·Updated
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
Affected Software
2 affected components
ABB T-MAC Plus=4.0-24
ABB T-MAC Plus=4.0-24
Event History
Jun 3, 2026
CVE Published
via MITRE·09:40 AM
Data Sourced
via MITRE·09:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-14773?
The severity of CVE-2025-14773 is rated as high, with a score of 8.
2
How do I fix CVE-2025-14773?
To fix CVE-2025-14773, ensure that input validation and output encoding are properly implemented in the ABB T-MAC Plus web application.
3
What impact does CVE-2025-14773 have?
CVE-2025-14773 allows attackers to execute arbitrary JavaScript in the context of a victim's browser through stored cross-site scripting.
4
Which versions of ABB T-MAC Plus are affected by CVE-2025-14773?
CVE-2025-14773 affects ABB T-MAC Plus versions 4.0-24.
5
Who is affected by CVE-2025-14773?
Users of the ABB T-MAC Plus web application are at risk due to CVE-2025-14773.