Historical intelligence backfill. This assessment covers reporting originally published on 2026-06-09 and was added to the RWP archive on 2026-09-07.
Trane Tracer SC+ had a diagnostic service that was pre-auth root on the cooling controller
CVE-2026-28252 through 28256 — auth bypass to SSH/root, pre-auth DoS, info leak, hardcoded credentials and decrypt constants. Trane's fix is Tracer SC+ v6.3 (1 March 2026).
Bottom line up front
CONFIRMED Same 9 June 2026 Team82 drop as the Vertiv UPS post, different product. Tracer SC+ (research: up to v5.20.1362 / affected through v6.2 depending on the CVE text) has CVE-2026-28252 — diagnostic service authentication bypass to root-level RCE/SSH; CVE-2026-28253 pre-auth DoS; CVE-2026-28254 sensitive disclosure; CVE-2026-28255 hardcoded global credentials; CVE-2026-28256 constants that decrypt config/backups. Trane: update to v6.3 or later (released 1 March 2026). Facilities Dive quotes complete BMS control from outside. No confirmed victim thermal event. Process impact: ASSESSED (cooling loss / thermal shutdown in a data hall or campus), UNKNOWN in the wild.
Keep separate from Vertiv: different CVEs, vendors, and patch trains. Same SANS talk.
Historical backfill of 9 June 2026 reporting; added 7 September 2026.
What happened
A diagnostic channel that should have been a vendor tool was a pre-auth door. Hardcoded secrets mean even a patched box needs credential/config rotation if it was reachable.
Why it mattered
HVAC failure in a dense compute room is not comfort. It is emergency power-off and hardware damage. Building management is in the data-center threat model.
Who / what was affected
Tracer SC+ fleets in data centers and other critical buildings. Internet or poorly segmented BMS VLANs are the condition.
Technical context
v6.3+. Isolate Tracer from the internet. Hunt diagnostic-service exposure. Rotate anything that the decrypt constants could have unlocked.
Exploitation / threat status at the time
CONFIRMED vuln chain and vendor patch.
UNKNOWN exploitation.
What defenders should have done
- Firmware inventory SC / SC+ / Concierge (related CVEs later appeared on Team82's dashboard for those SKUs).
- No diagnostic services on tenant networks.
- Couple with UPS monitoring — dual-path disruption.
RWP assessment
Confidence: High. Cooling controllers belong on the CISO's KEV-class list even when CISA has not put them in a water-sector PSA.
Defensive actions
- Patch to v6.3+.
- BMS VLAN + jump host.
- Thermal runbook that assumes hostile setpoints, not failed compressors.
Sources
- Claroty Team82 — Turning up the heat: hacking Trane HVAC controllers
- SecurityWeek — Critical HVAC and UPS vulnerabilities could let hackers disrupt data centers
- Facilities Dive — Vulnerabilities discovered in Trane, Vertiv data center products