CRITICAL vulnerabilities have been detected related to the SAUTER building controller, specifically CVE-2026-78319, which has a CVSS score of 9.3. This vulnerability allows unauthenticated remote code execution due to a Time-of-Check to Time-of-Use (TOCTOU) race condition. Affected versions include firmware for the modulo 6 below 4.0.0 and EY-modulo 5 below 7.0.0.
Although no active exploitation has been reported, a patch is available, and users are advised to update to newer firmware versions immediately to mitigate risks. The vulnerability was identified during a security hackathon and reported by CERT@VDE.