Vulnerabilities & Exploits · IoT / OT Attack

Default Mode Leaves ABB Door Systems Open

ABB left a building-access control in a state where the normal authentication check can be skipped from day one. That makes this a physical entry bypass, not a narrow edge case, because a live actuator can be used to open doors even when the system looks correctly deployed.

CISA’s republished advisory says CVE-2025-7705 affects all listed versions of the ABB Busch-Welcome 2 Wire Door Opener Actuator, including ABB Switch Actuator 4 DU -83330 and Switch actuator, door/light 4 DU -83330-500. ABB says the fix is on-site: toggle the mode switch from “Door-Open” to “Light,” switch back, then power-reset the system so it recalibrates on boot.

The risk persists anywhere compatibility mode is left enabled. Remote patching does not remove a default-on bypass in a physical access device; the system has to be reconfigured where it is installed.

1 source · May 28

CVE-2025-7705

NVD KEV

CVSS 6.8 MEDIUM: : Active Debug Code vulnerability in ABB Switch Actuator 4 DU-83330, ABB Switch actuator, door/light 4 DU… EPSS 0.2% (9th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-28

Every edition of this story: Default Mode Leaves ABB Door Systems Open

More from today