logo

The Risky Road Bringing Building Management Systems Online: Exploring the CEA-852 Standard

ID: 86307385-9201-5977-a16e-c886ee95dab1

STIX ID: report--86307385-9201-5977-a16e-c886ee95dab1

Feed Name: Claroty Team82

Threat Score
75/100

Date Published: 2026-04-08

Date Updated: 2026-04-17

Author: Amir Zaltzman

...
...

This report analyzes security weaknesses in the CEA-852 (LonTalk-over-IP) protocol and its implementations (IP-852, RNI, LPA), describing a flawed MD5-based HMAC authentication, default or optional keys, and vendor-specific packet types that allow remote reboot and firmware push. The weaknesses enable offline brute-force of the 16-byte pre-shared key (or trivial exploitation when keys are default/disabled), creating remote attack vectors against building management gateways (EnOcean/Echelon, Loytec) that can lead to denial-of-service or full compromise of systems bridging BACnet, Modbus, HTTP and other networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.