VORANT. Threat Intelligence Sign in Get the full feed

ABB door opener actuators ship with debug mode enabled by default, allowing attackers to…

high vulnerability

ABB door opener actuators ship with debug mode enabled by default, allowing attackers to bypass authentication and gain unauthorized physical building access.

ABB disclosed CVE-2025-7705 affecting all versions of its Busch-Welcome 2 Wire Door Opener Actuator product line, including Switch Actuator 4 DU and Switch actuator door/light 4 DU models. The vulnerability stems from a compatibility debug mode left enabled by default during manufacturing, classified as CWE-489 (Active Debug Code). Exploitation allows an attacker to bypass authentication mechanisms and gain unauthorized physical access to buildings where these systems control entry points.

The affected products are deployed worldwide in commercial facilities. ABB has issued a manual remediation procedure requiring on-site intervention: administrators must toggle the device's mode switch from 'Door-Open' to 'Light' mode, wait one second, switch back, then perform a power reset. This process forces the system to recalibrate and disable the debug mode automatically.

While no threat actors or active exploitation campaigns are mentioned in the advisory, the physical security implications are significant for facilities relying on these access control systems. ABB recommends customers apply the mitigation steps immediately and consult installation handbooks for proper security configuration. CISA has republished this advisory verbatim from ABB's CSAF-formatted disclosure.

Mentioned in this report

Vulnerabilities CVE-2025-7705

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-04

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free