logo

Examining the Legacy BMS LonTalk Protocol

ID: 2a06d58b-fe0d-58cf-94a2-f8daefcf657f

STIX ID: report--2a06d58b-fe0d-58cf-94a2-f8daefcf657f

Feed Name: Claroty Team82

Threat Score
60/100

Date Published: 2026-02-19

Date Updated: 2026-04-17

Author: Amir Zaltzman

...
...

Team82 reviews the legacy LonTalk protocol (CEA-709) and its IP-based extension (CEA-852), describing how the transition from dedicated Neuron chips to IP-based implementations increases attack surface for building management systems (BMS). The report outlines protocol features (network variables, SNVTs), availability of EnOcean/EnOcean GitHub stacks, and the security implications of vendor-specific management packets, noting many Internet-exposed controllers (identified via Censys) that use default MD5 keys or lack protections—creating opportunities for unauthorized access and remote manipulation of HVAC, lighting, and other critical building systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.