CVE-2025-13162
Received
Received - Intake
Uncontrolled Search Path Element in ABB Control Builder A and 800xA for Advant Master
Publication date: 2026-06-23
Last updated on: 2026-06-23
Assigner: Asea Brown Boveri Ltd. (ABB)
Description
Description
Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master.
This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| abb | control_builder_a | to 1.4/4 (exc) |
| abb | 800xa_for_advant_master | to 6.1.1-3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-427 | The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. |