CVE-2025-13778
Deferred
Deferred - Pending Action
Missing Authentication in ABB AWIN GW100/GW120 Enables Unauthorized Access
Publication date: 2026-03-13
Last updated on: 2026-05-19
Assigner: Asea Brown Boveri Ltd. (ABB)
Description
Description
Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| abb | awin_gw100 | From 2.0-0 (inc) to 2.0-1 (inc) |
| abb | awin_gw120 | From 1.2-0 (inc) to 1.2-1 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |