Historical intelligence backfill. This assessment covers reporting originally published on 2026-06-09 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

Trane Tracer SC+ had a diagnostic service that was pre-auth root on the cooling controller

CVE-2026-28252 through 28256 — auth bypass to SSH/root, pre-auth DoS, info leak, hardcoded credentials and decrypt constants. Trane's fix is Tracer SC+ v6.3 (1 March 2026).

RWP Ventures · 2026-09-07 · event 2026-06-09 · 2 min read · priority 8.5

Bottom line up front

CONFIRMED Same 9 June 2026 Team82 drop as the Vertiv UPS post, different product. Tracer SC+ (research: up to v5.20.1362 / affected through v6.2 depending on the CVE text) has CVE-2026-28252 — diagnostic service authentication bypass to root-level RCE/SSH; CVE-2026-28253 pre-auth DoS; CVE-2026-28254 sensitive disclosure; CVE-2026-28255 hardcoded global credentials; CVE-2026-28256 constants that decrypt config/backups. Trane: update to v6.3 or later (released 1 March 2026). Facilities Dive quotes complete BMS control from outside. No confirmed victim thermal event. Process impact: ASSESSED (cooling loss / thermal shutdown in a data hall or campus), UNKNOWN in the wild.

Keep separate from Vertiv: different CVEs, vendors, and patch trains. Same SANS talk.

Historical backfill of 9 June 2026 reporting; added 7 September 2026.

What happened

A diagnostic channel that should have been a vendor tool was a pre-auth door. Hardcoded secrets mean even a patched box needs credential/config rotation if it was reachable.

Why it mattered

HVAC failure in a dense compute room is not comfort. It is emergency power-off and hardware damage. Building management is in the data-center threat model.

Who / what was affected

Tracer SC+ fleets in data centers and other critical buildings. Internet or poorly segmented BMS VLANs are the condition.

Technical context

v6.3+. Isolate Tracer from the internet. Hunt diagnostic-service exposure. Rotate anything that the decrypt constants could have unlocked.

Exploitation / threat status at the time

CONFIRMED vuln chain and vendor patch.

UNKNOWN exploitation.

What defenders should have done

  1. Firmware inventory SC / SC+ / Concierge (related CVEs later appeared on Team82's dashboard for those SKUs).
  2. No diagnostic services on tenant networks.
  3. Couple with UPS monitoring — dual-path disruption.

RWP assessment

Confidence: High. Cooling controllers belong on the CISO's KEV-class list even when CISA has not put them in a water-sector PSA.

Defensive actions

  1. Patch to v6.3+.
  2. BMS VLAN + jump host.
  3. Thermal runbook that assumes hostile setpoints, not failed compressors.

Sources

  1. Claroty Team82 — Turning up the heat: hacking Trane HVAC controllers
  2. SecurityWeek — Critical HVAC and UPS vulnerabilities could let hackers disrupt data centers
  3. Facilities Dive — Vulnerabilities discovered in Trane, Vertiv data center products