CVE-2026-4293 Details
Description
The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser.
A cross-site scripting vulnerability has been identified in Kieback & Peter DDC building controllers, specifically in versions DDC4002, DDC4100, DDC4200, DDC4200-L, DDC4400, DDC4002e, DDC4200e, DDC4400e, DDC4020e, DDC4040e, and DDC520. This vulnerability allows JavaScript to be executed in the victim's browser, potentially giving an attacker control over the browser session.
For the DDC520, DDC4002e, DDC4200e, DDC4400e, DDC4020e, and DDC4040e controllers, Kieback & Peter recommends updating the firmware to the latest available version and restricting network access to the device. For the DDC4002e, DDC4200e, DDC4400e, DDC4020e, and DDC4040e controllers, users should update to version 1.23.5 or newer. For the DDC520, the recommended version is 1.24.2 or newer.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 20, 2026CISA-ADP
Assessed May 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-139-05.json | [email protected] | AdvisoryBundleRemedy |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-05 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Kieback & Peter DDC4002 | <= 1.24.1 (semver) |
CPE
Remediation
| |
| Kieback & Peter DDC4100 | All versions |
CPE
Remediation
| |
| Kieback & Peter DDC4200 | All versions |
CPE
Remediation
| |
| Kieback & Peter DDC4200-L | All versions |
CPE
Remediation
| |
| Kieback & Peter DDC4400 | All versions |
CPE
Remediation
| |
| Kieback & Peter DDC4002e | All versions |
CPE
Remediation
| |
| Kieback & Peter DDC4200e | All versions |
CPE
Remediation
| |
| Kieback & Peter DDC4400e | All versions |
CPE
Remediation
| |
| Kieback & Peter DDC4020e | All versions |
CPE
Remediation
| |
| Kieback & Peter DDC4040e | All versions |
CPE
Remediation
| |
| Kieback & Peter DDC520 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2026 | New CVE Received | [email protected] |
Volerion