CISA’s advisory on Kieback & Peter DDC Building Controllers is another reminder that building automation systems are now part of the cyber-risk surface, not just facilities infrastructure. These controllers are used to regulate and monitor HVAC and building operations, and Kieback & Peter’s own product information describes DDC systems as supporting building automation with BACnet, LON, KNX, DALI and other integrations. That level of connectivity is useful, naturally, because humans enjoy connecting everything and then acting surprised when attackers notice.

Organizations using such systems should not treat them as “set-and-forget” devices. They should verify affected models and firmware, apply vendor-recommended updates, restrict management access, isolate building automation networks from IT and guest networks, and continuously monitor for unusual access attempts. Smart buildings are only smart when the security architecture around them is equally mature. Otherwise, they are just very expensive doors, chillers and controllers waiting to become someone else’s remote-control project.


View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of the victim's browser. The following versions of Kieback & Peter DDC Building Controllers are affected: DDC4002 <=1.12.14 (CVE-2026-4293) DDC4100 <=1.12.14 (CVE-2026-4293) DDC4200 <=1.12.14 (CVE-2026-4293) DDC4200-L <=1.12.14 (CVE-2026-4293) DDC4400 <=1.12.14 (CVE-2026-4293) DDC4002e <=1.23.4 (CVE-2026-4293) DDC4200e <=1.23.4 (CVE-2026-4293) DDC4400e <=1.23.4 (CVE-2026-4293) DDC4020e <=1.23.4 (CVE-2026-4293) DDC4040e <=1.23.4 (CVE-2026-4293) DDC520 <=1.24.1 (CVE-2026-4293) CVSS Vendor Equipment Vulnerabilities v3 5.3 Kieback & Peter Kieback & Peter DDC Building Controllers Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Commercial Facilities, Communications, Financial Services, Food and Agriculture, Government Services and Facilities, Healthcare and Public Health, Information Technology Countries/Areas Deployed: Austria, China, France, Germany, United Arab Emirates Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-4293 The affected products are vulnerable to cross-site scripting (XSS), enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser. View CVE Details Affected Products Kieback & Peter DDC Building Controllers Vendor: Kieback & Peter Product Version: Kieback & Peter DDC4002: <=1.12.14, Kieback & Peter DDC410

Source: Kieback & Peter DDC Building Controllers via CISA Advisories — published 19 May 2026.