Zurück zur Übersicht

SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution

VDE-2026-093
Last update
01.09.2026 12:00
Published at
01.09.2026 12:00
Vendor(s)
Sauter AG
External ID
VDE-2026-093
CSAF Document

Summary

A vulnerability has been found in the firmware update process of SAUTER Building Controllers. The identified vulnerability could allow unauthorized code execution on affected controllers.

Impact

An attacker who successfully exploits this vulnerability may gain full control of the device, potentially affecting the operation, reliability, and security of connected building automation functions.

Affected Product(s)

Model no. Product name Affected versions
EY-RC504F*** ecos504 EY-modulo 5 embedded software version <7.0.0
EY-RC505F*** ecos505 EY-modulo 5 embedded software version <7.0.0
EY6LC12F011 modu612-LC modulo 6 embedded software version <4.0.0
EY6AS60F011 modu660-AS modulo 6 embedded software version <4.0.0
EY6AS80F021 modu680-AS modulo 6 embedded software version <4.0.0

Vulnerabilities

Expand / Collapse all

Published
01.09.2026 08:45
Weakness
Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
Summary

A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition.
An unauthenticated remote attacker could exploit this race condition to bypass intended security controls.
This may result in the execution of unauthorized code.

References

Remediation

On ecos504 (EY-RC504F) and ecos505 (EY-RC505F) update to firmware version 7.0.0. or newer.

On modu680-AS (EY6AS80F021), modu660-AS (EY6AS60F011)) and modu612-LC (EY6LC12F011), update to firmware version 4.0.0 or newer.

Contact your local SAUTER representative if you need further assistance.

Acknowledgments

Sauter AG thanks the following parties for their efforts:

  • CERT@VDE for coordination
  • Cyberdefence Campus Domotics Hackathon 2026 for We would like to express our gratitude to the organisers of the Cyberdefence Campus Domotics Hackathon 2026 for their kind invitation to participate and for their responsible disclosure of vulnerabilities. (see https://www.ar.admin.ch/en/news-cyd-campus-conference-2026-en )

Revision History

Version Date Summary
1.0.0 01.09.2026 12:00 Initial revision