Kieback & Peter DDC Building Controllers
This CISA advisory details a cross-site scripting (XSS) vulnerability affecting several versions of Kieback & Peter’s DDC Building Controllers. The vulnerability, CVE-2026-4293, allows an attacker to execute JavaScript code within the victim’s browser, potentially leading to unauthorized control. Building automation systems are vulnerable when directly accessible from untrusted networks, and the vendor recommends strict network segmentation and firmware updates to mitigate the risk.
The vulnerability, identified as CVE-2026-4293, resides in the Kieback & Peter DDC Building Controllers, specifically versions up to and including 1.12.14. This XSS vulnerability allows an attacker to inject and execute malicious JavaScript code within the user’s browser, effectively gaining control over the affected device. The advisory highlights the importance of securing building automation systems (BAS) due to their potential impact on critical infrastructure. The vendor recommends a defense-in-depth strategy, including network segmentation and restricting access to the web portal to trusted individuals.