Historical intelligence backfill. This assessment covers reporting originally published on 2026-02-19 and was added to the RWP archive on 2026-09-07.
LonTalk is still on the internet — Claroty counted a thousand exposed Echelon controllers
Team82's February 2026 protocol brief is not a 0-day dump. It is a map of 1990s building-bus packets sitting on default CEA-852 ports with default MD5 keys.
Bottom line up front
CONFIRMED On 19 February 2026 Claroty Team82 published a protocol brief on LonTalk (CEA-709 / ISO/IEC 14908), the 1990s Echelon bus still under many proprietary BMS stacks. Censys-style search in the post: 1,027 internet-exposed Echelon instances and 216 Loytec. Many speak CEA-852 LonTalk-over-IP on default ports 1628/1629. Industrial Cyber's recap matches: a large share use default MD5 keys or no signature at all. This is exposure research, not a named intrusion. OT process impact from this paper: UNKNOWN (no victim event). Physical effect is ASSESSED if an exposed controller is writable — HVAC/lighting/energy — not demonstrated in the wild here.
Historical backfill of 19 February 2026 reporting; added 7 September 2026.
What happened
LonTalk moved from serial to IP via CEA-852. Flexibility is the vulnerability. Follow-on April post (separate Daily Top) details packet types.
Why it mattered
BACnet did not delete LonTalk. Integrators still commission, address, and clear faults over the bus. If that bus is on the internet, "building automation" is a remote-admin protocol.
Who / what was affected
Internet-reachable Echelon/Loytec class devices. No named building.
Technical context
Find 1628/1629. Do not put LonTalk-over-IP on a public interface. Change HMAC keys off vendor defaults. Segment BMS from guest Wi-Fi.
Exploitation / threat status at the time
CONFIRMED exposure counts in Team82's search.
UNKNOWN in-the-wild exploitation of these specific listeners.
What defenders should have done
- External scan for LonTalk-over-IP.
- Treat default MD5 as no auth.
- Inventory which BMS still speaks LonWorks.
RWP assessment
Confidence: High on the protocol/exposure facts. This is the prequel to the EnOcean SmartServer RCE.
Defensive actions
- Pull LonTalk off WAN.
- Monitor unexpected CNIP/IP-852.
- Assume HVAC control if those ports answer.
Sources
- Claroty Team82 — Examining the Legacy BMS LonTalk Protocol
- Industrial Cyber — Team82 warns of LonTalk risks across BMS deployments
- Claroty Team82 — Exploring the CEA-852 standard