← Back to Feed

ABB KNX Update Tool

CVE-2026-12705

July 28, 2026 · CISA (US-CERT) · Severity: CRITICAL

This advisory describes a vulnerability in ABB KNX Update Tool, where the firmware image lacks integrity protection, affecting only legacy KNX devices that do not support KNX Secure. An attacker with physical bus access could render the product unusable. ABB will not issue a software fix due to the nature of the classic KNX protocol.

Key Takeaways

  • ABB KNX Update Tool versions up to 2.0.175 lack firmware integrity checks.
  • Exploitation requires physical bus access and exclusively affects legacy KNX devices.
  • ABB has no plans to remediate due to classic KNX protocol limitations.
☕ Buy a Coffee