# ABB Freelance Security Lock Bypassed via Keyboard Shortcuts—All Versions Affected


## The Threat


ABB has disclosed a critical authentication bypass vulnerability in its Freelance Security Lock, a control system lockdown mechanism designed to restrict access to underlying Windows operating system functions in industrial and manufacturing environments. The vulnerability—tracked as CVE-2025-7064—allows attackers with local access to bypass Freelance Operations entirely using undocumented keyboard combinations available on modern keyboards, potentially granting full administrative access to systems that are supposed to be hardened and isolated.


The vulnerability hinges on a dangerous design principle: security through obscurity. The special key combinations that trigger the bypass are neither documented in official product guides nor publicly disclosed, yet they exist in the software and can be discovered or shared among attackers. This is particularly concerning because ABB Freelance is widely deployed in critical manufacturing environments, power systems, and other industrial control systems (ICS) across the globe where such locks are meant to be the last line of defense against physical tampering.


The scope of impact is alarming. Every version of ABB Freelance Security Lock—spanning from Freelance 2013 through Freelance 2024, including all service packs and patch releases—is affected. The vulnerability requires local access to the system, meaning it targets scenarios where an attacker has physical access to a workstation or a facility where a Freelance Operations terminal is deployed. In operational technology (OT) environments, this threat model is not theoretical; insider threats, supply chain access, and compromised facility security are recurring concerns in critical infrastructure protection.


## Severity and Impact


| Metric | Details |

|---|---|

| CVE ID | CVE-2025-7064 |

| CVSS v3.1 Score | 6.6 (MEDIUM) |

| CVSS Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |

| Attack Vector | Local |

| Attack Complexity | Low |

| Privileges Required | Low (standard user) |

| User Interaction | None |

| Scope | Unchanged |

| Confidentiality Impact | Low |

| Integrity Impact | High |

| Availability Impact | Low |

| CWE | CWE-305: Authentication Bypass by Primary Weakness |


The CVSS 6.6 score reflects a medium severity rating, but the "High" integrity impact suggests that successful exploitation could allow attackers to modify critical system configurations, alter control logic, or compromise the integrity of industrial processes. The requirement for low privileges and the absence of user interaction make this vulnerability particularly dangerous in environments where physical security controls may be weak or where maintenance staff have standard user accounts.


## Affected Products


The vulnerability affects all versions of ABB Freelance Security Lock when installed with the following Freelance system versions:


  • ABB Freelance 2013 (all Security Lock versions)
  • ABB Freelance 2013 SP1 (all Security Lock versions)
  • ABB Freelance 2016 (all Security Lock versions)
  • ABB Freelance 2016 SP1 (all Security Lock versions)
  • ABB Freelance 2019 (all Security Lock versions)
  • ABB Freelance 2019 SP1 (all Security Lock versions)
  • ABB Freelance 2019 SP1 FP1 (all Security Lock versions)
  • ABB Freelance 2024 (all Security Lock versions)

  • Organizations using ABB Freelance in any of these releases—which spans over a decade of deployments—should assume their systems are vulnerable unless patched.


    ## Mitigations


    ABB has not yet released fixed versions of Freelance Security Lock as of this advisory. Organizations relying on Freelance Security Lock should implement the following interim measures:


    1. Restrict Physical Access: Enforce strict physical security controls around Freelance Operations terminals. Limit access to authorized personnel only and monitor access logs carefully.


    2. Implement Keyboard Restrictions: If feasible in your environment, consider using hardware-level keyboard controls or disabling specific keyboard functionality at the firmware or BIOS level to prevent special key combinations from functioning.


    3. Deploy Network Segmentation: Isolate Freelance systems on segmented networks with additional monitoring for unauthorized access attempts and privilege escalation.


    4. Enable Audit Logging: Ensure comprehensive audit logging is enabled for all user actions on Freelance systems. Monitor logs for suspicious key sequences or login attempts outside normal business hours.


    5. Review Access Controls: Audit user accounts with access to Freelance systems and implement the principle of least privilege. Revoke unnecessary local administrative rights.


    6. Monitor for Exploitation: Watch for unusual activity patterns, such as rapid key sequences or attempts to access system administration tools via keyboard shortcuts.


    7. Contact ABB PSIRT: For detailed mitigation guidance specific to your deployment, consult ABB's official security advisory 7PAA020361 and engage directly with ABB Product Security and Incident Response Team (PSIRT).


    Organizations should prioritize applying official patches when ABB releases them. Until then, defense-in-depth strategies combining physical security, network isolation, and behavioral monitoring are essential.


    ## References


  • [ABB PSIRT Security Advisory 7PAA020361 (PDF)](https://search.abb.com/library/Download.aspx?DocumentID=7PAA020361&LanguageCode=en&Action=Launch)
  • [ABB PSIRT CSAF Advisory (JSON)](https://psirt.abb.com/csaf/2026/7paa020361.json)
  • [CVE-2025-7064 Details](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-7064)
  • [CWE-305: Authentication Bypass by Primary Weakness](https://cwe.mitre.org/data/definitions/305.html)

  • ---


    ## HackWire Analysis


    This vulnerability exposes a fundamental flaw in industrial control system security: the belief that obscurity can substitute for robust design. ABB's reliance on undocumented keyboard shortcuts as part of its security posture is a critical failure that should alarm every organization relying on Freelance Security Lock.


    The pattern here is particularly troubling because it's not unique. Keyboard-based exploits in locked-down environments have a long history in ICS security. Similar bypass techniques have been documented in other industrial systems where designers assumed that special key combinations would remain hidden or that the complexity of finding them would deter attackers. This advisory proves otherwise—and it's been true for years, potentially across hundreds of deployed systems.


    What's more alarming is the timeline. This vulnerability has existed since at least Freelance 2013, meaning organizations may have had vulnerable systems in production for over a decade. Some may never have known. The fact that all versions from 2013 through 2024 are affected suggests this wasn't a recent regression but rather an architectural weakness that persisted through multiple major releases and service packs.


    For defenders, this is a wake-up call about the limits of perimeter-based industrial control security. If your Freelance Security Lock is your primary defense against local attacks, you're underestimating the threat. Attackers with facility access—whether they're disgruntled insiders, supply chain infiltrators, or nation-state actors conducting pre-attack reconnaissance—now have a direct path to bypass your security controls.


    The remediation path is unclear. ABB has published the advisory but has not yet released fixed versions, leaving organizations in a precarious position. Until patches arrive, the mitigation burden falls entirely on customers to compensate with layered defenses, which is an uncomfortable position for critical infrastructure operators.


    Organizations in manufacturing, utilities, and other critical sectors should escalate this to their security leadership immediately and begin implementing compensating controls. This isn't a vulnerability you can safely ignore while waiting for a patch.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)