Back

MEDIUM

Kieback & Peter DDC Building Controllers Cross-site Scripting

Published May 20, 2026

Description

The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser.

Affected products

Remediation

Vendor solution

For DDC520, DDC4002e, DDC4200e, DDC4400e, DDC4020e, and DDC4040e controllers, update the firmware to the latest available version: 

* DDC4002e: Update to version 1.23.5 or newer * DDC4200e: Update to version 1.23.5 or newer * DDC4400e: Update to version 1.23.5 or newer * DDC4020e: Update to version 1.23.5 or newer * DDC4040e: Update to version 1.23.5 or newer * DDC520: Update to version 1.24.2 or newer

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published May 20, 2026
Updated May 20, 2026
Reserved Mar 16, 2026
CISA Vulnrichment
Updated May 20, 2026
NVD
Status Deferred
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner icscert
Published May 20, 2026
Updated May 20, 2026
Exploited since n/a
EUVD-2026-31125