Summary
A vulnerability has been found in the firmware update process of SAUTER Building Controllers. The identified vulnerability could allow unauthorized code execution on affected controllers.
Impact
An attacker who successfully exploits this vulnerability may gain full control of the device, potentially affecting the operation, reliability, and security of connected building automation functions.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| EY-RC504F*** | ecos504 | EY-modulo 5 embedded software version <7.0.0 |
| EY-RC505F*** | ecos505 | EY-modulo 5 embedded software version <7.0.0 |
| EY6LC12F011 | modu612-LC | modulo 6 embedded software version <4.0.0 |
| EY6AS60F011 | modu660-AS | modulo 6 embedded software version <4.0.0 |
| EY6AS80F021 | modu680-AS | modulo 6 embedded software version <4.0.0 |
Vulnerabilities
Expand / Collapse allA service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition.
An unauthenticated remote attacker could exploit this race condition to bypass intended security controls.
This may result in the execution of unauthorized code.
Remediation
On ecos504 (EY-RC504F) and ecos505 (EY-RC505F) update to firmware version 7.0.0. or newer.
On modu680-AS (EY6AS80F021), modu660-AS (EY6AS60F011)) and modu612-LC (EY6LC12F011), update to firmware version 4.0.0 or newer.
Contact your local SAUTER representative if you need further assistance.
Acknowledgments
Sauter AG thanks the following parties for their efforts:
- CERT@VDE for coordination
- Cyberdefence Campus Domotics Hackathon 2026 for We would like to express our gratitude to the organisers of the Cyberdefence Campus Domotics Hackathon 2026 for their kind invitation to participate and for their responsible disclosure of vulnerabilities. (see https://www.ar.admin.ch/en/news-cyd-campus-conference-2026-en )
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 09/01/2026 12:00 | Initial revision |