Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-09 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

Danfoss AK-SM 800A hid a "code of the day" that skipped the login

Same DEF CON 34 refrigeration track as Copeland, different vendor — auth bypass, command injection RCE, Nginx config injection. Danfoss R4.3.1 / patch 4.2 depending on CVE.

RWP Ventures · 2026-09-07 · event 2026-08-09 · 1 min read · priority 8.1

Bottom line up front

CONFIRMED Team82, 9 August 2026, Danfoss AK-SM 800A web management: hidden "code-of-the-day" authentication that bypasses normal login; command injection to RCE; authenticated Nginx directive injection that can DoS or steer web traffic. Coordinated disclosure; Danfoss firmware R4.3.1. Team82's CVE notes on the same page family include CVE-2025-41451 and CVE-2025-41450 (improper authentication, CVSS 7.6, "install latest patch with number 4.2"). Same conference as Copeland XWEB; keep as a separate post — different vendor, CVE train, and bypass primitive. Lab/process impact: ASSESSED (refrigeration disruption / spoilage) from Team82's framing; production victims UNKNOWN.

Historical backfill of 9 August 2026 reporting; added 7 September 2026.

What happened

A vendor support backdoor pattern — rotating daily code — became the internet's login. Nginx injection is the persistence/DoS layer once you are in.

Why it mattered

Refrigeration OEMs still ship web UIs that were designed for a technician on the LAN. Two vendors in one DEF CON slot means the class is the story: cold-chain supervisory controllers.

Who / what was affected

AK-SM 800A / AK-SM8xxA series as named. Internet-exposed management interfaces.

Technical context

Patch R4.3.1 / 4.2 as vendor directs. Disable code-of-the-day if a later build still exposes it. No WAN to the web UI.

Exploitation / threat status at the time

CONFIRMED vulns + patch.

UNKNOWN exploitation.

What defenders should have done

  1. Firmware now.
  2. Hunt "code of the day" / undocumented auth.
  3. Independent temperature monitoring (same as Copeland).

RWP assessment

Confidence: High on Team82/Danfoss facts. Pair with the Copeland post for cold-chain owners.

Defensive actions

  1. Patch both Copeland and Danfoss fleets in one change window.
  2. Remove refrigeration HMIs from Shodan.
  3. Spoilage + setpoint mismatch as a cyber ticket.

Sources

  1. Claroty Team82 — Freeze the controller, defrost the food
  2. TipRanks / Claroty LinkedIn recap — Danfoss and Copeland refrigeration research at DEF CON 34
  3. Claroty — Copeland companion research (same talk, different product)