Executive brief
Kieback & Peter DDC building controllers, which are used to manage heating, ventilation, and air conditioning systems in commercial and government facilities, are affected by a security flaw. An attacker could use this vulnerability to execute malicious code in a user's web browser when they interact with the controller's web interface. This could allow an attacker to hijack a user's session or manipulate the building management interface, potentially leading to unauthorized changes in building operations.
Technical details
The Kieback & Peter DDC building controllers contain a Cross-Site Scripting (XSS) vulnerability (CWE-79) due to improper neutralization of input during web page generation. An unauthenticated remote attacker can exploit this by injecting malicious JavaScript into the web interface. If a user visits the compromised page, the script executes in their browser context, potentially allowing the attacker to steal session tokens or perform actions on behalf of the user. Firmware updates are available for 'e' series and DDC520 models (v1.23.5 and v1.24.2 respectively), while older DDC4xxx models are end-of-maintenance and require network isolation as a mitigation.
Affected products
- Kieback & Peter DDC4002 <=1.12.14
- Kieback & Peter DDC4100 <=1.12.14
- Kieback & Peter DDC4200 <=1.12.14
- Kieback & Peter DDC4200-L <=1.12.14
- Kieback & Peter DDC4400 <=1.12.14
- Kieback & Peter DDC4002e <=1.23.4
- Kieback & Peter DDC4200e <=1.23.4
- Kieback & Peter DDC4400e <=1.23.4
- Kieback & Peter DDC4020e <=1.23.4
- Kieback & Peter DDC4040e <=1.23.4
- Kieback & Peter DDC520 <=1.24.1
Timeline
- 2026-05-19: advisory: CISA published ICSA-26-139-05
- 2026-05-20: disclosed: CVE-2026-4293 published to NVD