CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-14771

criticalcovered by 1 sourcefirst seen 2026-07-14
View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways. The following versions of ABB T-MAC Plus are affected: T-MAC Plus 4.0-24 (CVE-2025-14771, CVE-2025-14772, CVE-2025-14773, CVE-2025-14774) CVSS Vendor Equipment Vulnerabilities v3 9.9 ABB ABB T-MAC Plus Files or Directories Accessible to External Parties, Authorization Bypass Through User-Controlled Key, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Incorrect Authorization Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-14771 File Disclosure in ABB T-MAC Plus web application allows authenticated users to exfiltrate files containing sensitive information via crafted HTTP GET request. View CVE Details Affected Products ABB T-MAC Plus Vendor: ABB Product Version: ABB T-MAC Plus 4.0-24 Product Status: known_affected Remediations Vendor fix ABB has investigated these vulnerabilities to provide adequate protection to customers. The problem is corrected in the following product versions: T-MAC Plus version 4.0-25 ABB recommends that customers apply the update at earliest convenience. Mitigation The misconfigurations on the IIS server, which were reported to security auditing, have been corrected. File Browsing Feature was enabled on that IIS server. That feature along with the default IIS site has been removed. Workaround Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. ABB has tested the following workarounds. Although these workarounds will not co

CSIRTS triage

vendor: ABBproduct: T-MAC PlusOtheraffected: 4.0-24
What
Multiple vulnerabilities could allow an attacker to compromise the system.
Who is affected
Users of ABB T-MAC Plus version 4.0-24.
Urgency
Remediation is critical due to the high severity of the vulnerabilities.
Action
Update to a version that resolves the identified vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2025-14771

Get an email if CVE-2025-14771 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2025-14771

CVE.org record

Embed the live status

CVE-2025-14771 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-14771 status](https://www.csirts.com/badge/CVE-2025-14771)](https://www.csirts.com/cve/CVE-2025-14771)