CVE-2024-5539: Automated Logic Webctrl

Critical severity, CVSS 9.2. EPSS: 0.3% chance of exploitation in the next 30 days.

The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server.

Affected products

Published 2025-11-27. Last modified 2026-06-17.