


Perceptive Security
SOC/SIEM Consultancy

ABB Busch-Welcome 2 Wire Door Opener Actuator
Published:
28 mei 2026 om 12:00:00
Alert date:
28 mei 2026 om 17:06:19
Source:
cisa.gov
Mobile & IoT, Critical Infrastructure
ABB Busch-Welcome 2 Wire Door Opener Actuator contains an authentication bypass vulnerability (CVE-2025-7705) due to compatibility mode being enabled by default. The vulnerability affects all versions of Switch Actuator 4 DU and Switch actuator door/light 4 DU models. An attacker exploiting this vulnerability could gain unauthorized physical access to buildings where the product is installed. The vulnerability is caused by active debug code (CWE-489) and has a CVSS v3.1 score of 6.8 (Medium). ABB has provided mitigation steps involving toggling the mode switch and performing a power reset to recalibrate the system. The vulnerability affects commercial facilities worldwide.
Technical details
Mitigation steps:
Affected products:
ABB Busch-Welcome 2 Wire Door Opener Actuator
Related links:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-04
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-04.json
https://www.cve.org/CVERecord?id=CVE-2025-7705
https://cwe.mitre.org/data/definitions/489.html
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
