CVE-2026-28252
EUVD-2026-1162912.03.2026, 18:16
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| trane | tracer_sc_firmware | 𝑥 ≤ 4.4 |
| trane | tracer_sc_firmware | 4.4:service_pack1 |
| trane | tracer_sc_firmware | 4.4:service_pack2 |
| trane | tracer_sc_firmware | 4.4:service_pack3 |
| trane | tracer_sc_firmware | 4.4:service_pack4 |
| trane | tracer_sc_firmware | 4.4:service_pack5 |
| trane | tracer_sc_firmware | 4.4:service_pack6 |
| trane | tracer_sc\+_firmware | 𝑥 < 6.3.2310 |
| trane | tracer_concierge | 𝑥 < 6.3.2310 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration