Historical intelligence backfill. This assessment covers reporting originally published on 2026-04-08 and was added to the RWP archive on 2026-09-07.
CEA-852 made LonTalk a remote protocol — optional HMAC is the design defect
Team82's April 2026 standard teardown shows IP-852, RNI, and LPA packet types, optional HMAC on IP-852, and remote disruption paths once LonTalk rides TCP/UDP.
Bottom line up front
CONFIRMED On 8 April 2026 Team82 published the IP-layer companion to its LonTalk brief. CEA-852 carries LonTalk over TCP/UDP as IP-852, RNI, and LPA. HMAC is optional on IP-852 (mandatory on RNI/LPA) and uses MD5. Team82 describes undocumented authentication behavior and packet types that can disrupt services, plus remote attack vectors against internet-exposed BMS gateways. Facilities Dive later summarized the same "LonTalk under proprietary BMS" point and internet-accessible controllers on default ports. Not a victim report. Process impact: ASSESSED for exposed gateways, UNKNOWN in the wild.
Historical backfill of 8 April 2026 reporting; added 7 September 2026.
What happened
The standard's security flag is a configuration choice, not a floor. Once LonTalk is IP, every BMS command is a packet you can spoof if HMAC is off or keyed with a default.
Why it mattered
This is why the EnOcean SmartServer timezone packet became root RCE three weeks later. The protocol invited unauthenticated control-plane messages.
Who / what was affected
BMS/BAS using LonTalk-over-IP. No named campus.
Technical context
Disable IP-852 on WAN-facing NICs. Require HMAC with non-default keys. IDS for CNIP headers. Prefer BACnet/SC or vendor VPNs over naked CEA-852.
Exploitation / threat status at the time
CONFIRMED Team82 protocol weaknesses.
UNKNOWN exploitation of CEA-852 as a named campaign.
What defenders should have done
- Treat ports 1628/1629 as PLC-class, not "building IT."
- Turn security flags on; rotate keys.
- Read the EnOcean follow-up as the implementation of this standard.
RWP assessment
Confidence: High on the standard analysis. Design-level, not a one-off CVE.
Defensive actions
- Network ACL deny IP-852 from untrusted nets.
- Asset inventory tagged LonWorks.
- Tabletop: forged setpoint packet to HVAC.
Sources
- Claroty Team82 — Exploring the CEA-852 standard
- Facilities Dive — Legacy BMS protocol poses threat to building systems
- Claroty Team82 — Examining the Legacy BMS LonTalk Protocol