Junglewise Threat Intelligence

CVE-2026-78319: Sauter Building Controllers firmware update TOCTOU race condition

CVE-2026-78319 · Severity: info · CVSS 9.8 · Published 2026-09-01

Executive brief

Sauter Building Controllers (used for HVAC, lighting, and other building automation systems) contain a race condition vulnerability in their firmware update process that allows an unauthenticated attacker to execute arbitrary code on the device. Successful exploitation could give an attacker full control of the controller, disrupting critical building operations and compromising the security and reliability of connected systems across an entire facility.

Technical details

The vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition (CWE-367) in a service running on the affected firmware. An unauthenticated remote attacker can exploit this race condition over the network to bypass intended security controls during the firmware update mechanism, leading to unauthorized code execution. No authentication is required and no user interaction is needed. An attacker can achieve full control of the device. Patches are available: ecos504/ecos505 require firmware 7.0.0 or newer; modu612-LC, modu660-AS, and modu680-AS require firmware 4.0.0 or newer.

Affected products

  • Sauter ecos504 <7.0.0
  • Sauter ecos505 <7.0.0
  • Sauter modu612-LC <4.0.0
  • Sauter modu660-AS <4.0.0
  • Sauter modu680-AS <4.0.0

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Firmware 7.0.0 for ecos504/ecos505; firmware 4.0.0 for modu612-LC/modu660-AS/modu680-AS

References