← Back to Feed
ABB KNX Update Tool
CVE-2026-12705
July 28, 2026 · CISA (US-CERT) · Severity: CRITICAL
This advisory describes a vulnerability in ABB KNX Update Tool, where the firmware image lacks integrity protection, affecting only legacy KNX devices that do not support KNX Secure. An attacker with physical bus access could render the product unusable. ABB will not issue a software fix due to the nature of the classic KNX protocol.
Key Takeaways
- ABB KNX Update Tool versions up to 2.0.175 lack firmware integrity checks.
- Exploitation requires physical bus access and exclusively affects legacy KNX devices.
- ABB has no plans to remediate due to classic KNX protocol limitations.