CVE-2026-28255
EUVD-2026-1163512.03.2026, 18:16
A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| trane | tracer_sc_firmware | 𝑥 ≤ 4.4 |
| trane | tracer_sc_firmware | 4.4:service_pack1 |
| trane | tracer_sc_firmware | 4.4:service_pack2 |
| trane | tracer_sc_firmware | 4.4:service_pack3 |
| trane | tracer_sc_firmware | 4.4:service_pack4 |
| trane | tracer_sc_firmware | 4.4:service_pack5 |
| trane | tracer_sc_firmware | 4.4:service_pack6 |
| trane | tracer_sc\+_firmware | 𝑥 < 6.3.2310 |
| trane | tracer_concierge | 𝑥 < 6.3.2310 |
𝑥
= Vulnerable software versions