Security/ ics · physical security · vulnerability · abb

ABB Door Hardware Bug Unlocks Buildings via Default Debug Mode

A default-on compatibility mode in ABB's Busch-Welcome door actuators bypasses authentication, and the only fix is a manual toggle-and-reboot at each site.

ABB Door Hardware Bug Unlocks Buildings via Default Debug Mode

A widely deployed ABB building-entry controller ships with a debug compatibility mode enabled by default - one that disables authentication and could let an unauthorized person walk through a secured door.

ABB disclosed CVE-2025-7705 in its Busch-Welcome 2 Wire Door Opener Actuator, covering all versions of the Switch Actuator 4 DU and its door-light variant. The flaw is classified as CWE-489 - active debug code left on in production - and stems from compatibility mode being enabled out of the box. An attacker with physical access to the device can exploit the misconfiguration to bypass authentication and gain unauthorized entry to the facility the unit protects. CISA scored it 6.8 (Medium), though "an intruder walks into your building" is not how most organizations would describe a medium-severity outcome.

There is no firmware patch. ABB's remediation is a manual field procedure: toggle the mode switch from Door-Open to Light mode, wait one second, toggle it back, then power-cycle the unit. For any organization with these actuators spread across multiple commercial facilities, that means a technician visit to every affected installation. The fix works, but the exposure window is entirely a function of how fast you can physically reach every device.

Debug code shipping enabled by default in hardware that controls physical access is the same class of mistake that plagued cheap consumer routers and IP cameras for a decade - it has just turned up somewhere with considerably higher-stakes doors.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →