CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-12705

criticalCVSS 6.4covered by 2 sourcesfirst seen 2026-07-17
View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures. The following versions of ABB KNX Update Tool are affected: KNX Update Tool (ABB) <=2.0.175 (CVE-2026-12705) KNX Update Tool (BJE) <=2.0.175 (CVE-2026-12705) CVSS Vendor Equipment Vulnerabilities v3 6.4 ABB ABB KNX Update Tool Missing Support for Integrity Check Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-12705 There is no protection of the integrity of the firmware image. This applies exclusively to legacy KNX products View CVE Details Affected Products ABB KNX Update Tool Vendor: ABB Product Version: KNX Update Tool (ABB) <=2.0.175, KNX Update Tool (BJE) <=2.0.175 Product Status: known_affected Remediations Mitigation Due to the nature of the classic KNX protocol stack and security concept, there are no options to resolve the vulnerability with a software update on a technical level. ABB recommends to follow general security recommendations listed in the security guideline (see References and General security recommendations). In addition, it shall be avoided to control sensitive functionality by legacy KNX device

CSIRTS triage

What
A vulnerability could cause the product to become unusable if exploited.
Who is affected
Users of classic KNX devices that do not support the latest KNX Secure standard.
Urgency
Remediation is critical as exploitation could render devices unusable.
Action
No corrective measures are planned due to the nature of the devices.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-12705

Get an email if CVE-2026-12705 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-12705

CVE.org record

Embed the live status

CVE-2026-12705 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-12705 status](https://www.csirts.com/badge/CVE-2026-12705)](https://www.csirts.com/cve/CVE-2026-12705)