- CVE: CVE-2026-78319
- CVSS: 9.3 (Critical · CVSSv4)
- Product: Sauter modu680-AS
- Affected: 1.0.0
- Impact: TOCTOU Vulnerability in file exchange
- Status: No confirmed exploitation yet
- Patched in: 4.0.0, 7.0.0
- Action: Update to 4.0.0, 7.0.0 now
TL;DR
CERT@VDE published full details of CVE-2026-78319 on September 1, 2026. This SAUTER building controller vulnerability lets an unauthenticated remote attacker run code on affected devices. It carries a CVSS score of 9.8.
Why It Matters
SAUTER controllers manage heating, ventilation, and other building automation tasks. Therefore, a remote flaw threatens the safety and reliability of physical infrastructure. An attacker who wins the race can seize full control of the device.
Researchers found the SAUTER building controller vulnerability during the Cyberdefence Campus Domotics Hackathon 2026. They then reported it responsibly through CERT@VDE.
How the Attack Works
The root cause is a Time-of-Check to Time-of-Use (TOCTOU) race condition, tracked as CWE-367. A service on the device checks a file, then uses it a moment later.
An attacker changes that file between the two steps. As a result, the firmware update process accepts unauthorized content. This bypasses intended security controls and can execute attacker code. This report withholds any exploit code.
Exploitation Status
No public proof-of-concept exploit has been confirmed. Likewise, no active exploitation in the wild has been reported so far.
Affected Versions
The flaw affects modulo 6 firmware below version 4.0.0. It also affects EY-modulo 5 firmware below version 7.0.0. Impacted hardware includes the ecos504, ecos505, modu612-LC, modu660-AS, and modu680-AS.
Patch and Mitigation Steps
SAUTER released fixed firmware for both product lines. Update modulo 6 devices to version 4.0.0 or newer. Update EY-modulo 5 devices to version 7.0.0 or newer. In addition, enable downgrade protection after the update.
If You Cannot Patch Now
Restrict device and network access using current best practices. You can review remediation specifics in the official CERT@VDE advisory VDE-2026-093. Still, applying the firmware update remains the only full fix.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!