Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-09 and was added to the RWP archive on 2026-09-07.
Danfoss AK-SM 800A hid a "code of the day" that skipped the login
Same DEF CON 34 refrigeration track as Copeland, different vendor — auth bypass, command injection RCE, Nginx config injection. Danfoss R4.3.1 / patch 4.2 depending on CVE.
Bottom line up front
CONFIRMED Team82, 9 August 2026, Danfoss AK-SM 800A web management: hidden "code-of-the-day" authentication that bypasses normal login; command injection to RCE; authenticated Nginx directive injection that can DoS or steer web traffic. Coordinated disclosure; Danfoss firmware R4.3.1. Team82's CVE notes on the same page family include CVE-2025-41451 and CVE-2025-41450 (improper authentication, CVSS 7.6, "install latest patch with number 4.2"). Same conference as Copeland XWEB; keep as a separate post — different vendor, CVE train, and bypass primitive. Lab/process impact: ASSESSED (refrigeration disruption / spoilage) from Team82's framing; production victims UNKNOWN.
Historical backfill of 9 August 2026 reporting; added 7 September 2026.
What happened
A vendor support backdoor pattern — rotating daily code — became the internet's login. Nginx injection is the persistence/DoS layer once you are in.
Why it mattered
Refrigeration OEMs still ship web UIs that were designed for a technician on the LAN. Two vendors in one DEF CON slot means the class is the story: cold-chain supervisory controllers.
Who / what was affected
AK-SM 800A / AK-SM8xxA series as named. Internet-exposed management interfaces.
Technical context
Patch R4.3.1 / 4.2 as vendor directs. Disable code-of-the-day if a later build still exposes it. No WAN to the web UI.
Exploitation / threat status at the time
CONFIRMED vulns + patch.
UNKNOWN exploitation.
What defenders should have done
- Firmware now.
- Hunt "code of the day" / undocumented auth.
- Independent temperature monitoring (same as Copeland).
RWP assessment
Confidence: High on Team82/Danfoss facts. Pair with the Copeland post for cold-chain owners.
Defensive actions
- Patch both Copeland and Danfoss fleets in one change window.
- Remove refrigeration HMIs from Shodan.
- Spoilage + setpoint mismatch as a cyber ticket.
Sources
- Claroty Team82 — Freeze the controller, defrost the food
- TipRanks / Claroty LinkedIn recap — Danfoss and Copeland refrigeration research at DEF CON 34
- Claroty — Copeland companion research (same talk, different product)