ABB T-MAC Plus Multiple Vulnerabilities (File Disclosure, Broken Access Control, Stored XSS, DoS)
First seen Jul 16, 2026 · Updated Jul 16, 2026 · CVSS 9.9
ABB disclosed four vulnerabilities in T-MAC Plus 4.0-24, a Terminal Management System used in chemical, petroleum, and bulk terminal operations. The most severe issue (CVSS 9.9) allows authenticated users to exfiltrate sensitive files via crafted HTTP GET requests due to IIS misconfiguration, while other flaws enable privilege escalation, stored XSS, and physical-access-based denial of service against Card Reader services. ABB has released version 4.0-25 to remediate all four issues.
Technical Analysis
CVE-2025-14771 (CVSS 9.9) is a file disclosure vulnerability caused by IIS File Browsing misconfiguration, allowing authenticated attackers to retrieve arbitrary sensitive files via crafted GET requests. CVE-2025-14772 (CVSS 8.8) stems from broken access control (CWE-639) letting low-privileged users (e.g., Customer role) perform administrative operations. CVE-2025-14773 (CVSS 8.0) is a DOM-based stored XSS (CWE-79) enabling authenticated users to inject and execute arbitrary JavaScript in the web application. CVE-2025-14774 (CVSS 7.4) involves an insecure network protocol allowing an attacker with physical access to spoof a Card Reader device and trigger a denial-of-service via a crafted message, requiring manual restart. These are OT/industrial terminal management vulnerabilities with no direct AI agent integration or exposed API surfaces described, so no plausible AI agent system impact is asserted.
Affected Systems
ABB T-MAC Plus version 4.0-24 (web application and Card Reader communication protocol components); IIS server hosting the T-MAC Plus web application
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided; vulnerabilities pertain to configuration flaws and application logic rather than known malware/attack artifacts
Remediation Steps
- 1
Upgrade to T-MAC Plus 4.0-25
Apply the vendor-supplied update that corrects all four vulnerabilities as soon as possible.
- 2
Fix IIS misconfiguration
Disable File Browsing feature and remove the default IIS site to prevent unauthorized file disclosure.
- 3
Review and enforce role-based access controls
Verify that user roles (Admin, Customer, Operator) have correctly scoped privileges to prevent unauthorized administrative actions.
- 4
Network segmentation
Isolate control system networks and Card Reader communication from business networks and the internet; restrict physical access to serial devices.
- 5
Use secure remote access
Employ VPNs with up-to-date patching for any required remote access to T-MAC Plus systems.
- 6
Monitor and report
Follow internal incident response procedures and report suspected exploitation to CISA.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.