Historical intelligence backfill. This assessment covers reporting originally published on 2026-04-08 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

CEA-852 made LonTalk a remote protocol — optional HMAC is the design defect

Team82's April 2026 standard teardown shows IP-852, RNI, and LPA packet types, optional HMAC on IP-852, and remote disruption paths once LonTalk rides TCP/UDP.

RWP Ventures · 2026-09-07 · event 2026-04-08 · 1 min read · priority 7.6

Bottom line up front

CONFIRMED On 8 April 2026 Team82 published the IP-layer companion to its LonTalk brief. CEA-852 carries LonTalk over TCP/UDP as IP-852, RNI, and LPA. HMAC is optional on IP-852 (mandatory on RNI/LPA) and uses MD5. Team82 describes undocumented authentication behavior and packet types that can disrupt services, plus remote attack vectors against internet-exposed BMS gateways. Facilities Dive later summarized the same "LonTalk under proprietary BMS" point and internet-accessible controllers on default ports. Not a victim report. Process impact: ASSESSED for exposed gateways, UNKNOWN in the wild.

Historical backfill of 8 April 2026 reporting; added 7 September 2026.

What happened

The standard's security flag is a configuration choice, not a floor. Once LonTalk is IP, every BMS command is a packet you can spoof if HMAC is off or keyed with a default.

Why it mattered

This is why the EnOcean SmartServer timezone packet became root RCE three weeks later. The protocol invited unauthenticated control-plane messages.

Who / what was affected

BMS/BAS using LonTalk-over-IP. No named campus.

Technical context

Disable IP-852 on WAN-facing NICs. Require HMAC with non-default keys. IDS for CNIP headers. Prefer BACnet/SC or vendor VPNs over naked CEA-852.

Exploitation / threat status at the time

CONFIRMED Team82 protocol weaknesses.

UNKNOWN exploitation of CEA-852 as a named campaign.

What defenders should have done

  1. Treat ports 1628/1629 as PLC-class, not "building IT."
  2. Turn security flags on; rotate keys.
  3. Read the EnOcean follow-up as the implementation of this standard.

RWP assessment

Confidence: High on the standard analysis. Design-level, not a one-off CVE.

Defensive actions

  1. Network ACL deny IP-852 from untrusted nets.
  2. Asset inventory tagged LonWorks.
  3. Tabletop: forged setpoint packet to HVAC.

Sources

  1. Claroty Team82 — Exploring the CEA-852 standard
  2. Facilities Dive — Legacy BMS protocol poses threat to building systems
  3. Claroty Team82 — Examining the Legacy BMS LonTalk Protocol