Cross-site scripting vulnerability (CVE-2026-4293) in Kieback & Peter DDC building…
Cross-site scripting vulnerability (CVE-2026-4293) in Kieback & Peter DDC building controllers allows attackers to execute JavaScript in victim browsers.
CISA has published an advisory for a cross-site scripting (XSS) vulnerability affecting multiple Kieback & Peter DDC building automation controllers used in critical infrastructure sectors globally. The vulnerability, tracked as CVE-2026-4293, allows attackers to execute arbitrary JavaScript in the context of a victim's browser when accessing the controller's web portal, potentially enabling session hijacking or further attacks. Eleven product models are affected across three firmware branches, with versions up to 1.12.14, 1.23.4, and 1.24.1 impacted.
Five legacy models (DDC4002, DDC4100, DDC4200, DDC4200-L, DDC4400) are end-of-maintenance and will not receive patches. For these devices, the vendor recommends strict network segmentation, disabling the web portal if not needed, and restricting access to trusted users only. Six newer models have firmware updates available: DDC4002e through DDC4040e should update to version 1.23.5 or newer, while DDC520 should update to 1.24.2 or newer.
The vendor emphasizes that these controllers are designed for closed building automation networks and should never be directly exposed to the Internet. CISA recommends implementing defense-in-depth strategies, network segmentation with firewalls separating OT zones, and using secure remote access methods like VPNs when necessary. The advisory affects multiple critical infrastructure sectors including commercial facilities, healthcare, government, and financial services across several countries.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-05
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free