CVE-2026-4293: Kieback & Peter DDC4002
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser.
Affected products
- Kieback & Peter DDC4002: up to and including 1.12.14
- Kieback & Peter DDC4002E: up to and including 1.23.4
- Kieback & Peter DDC4020E: up to and including 1.23.4
- Kieback & Peter DDC4040E: up to and including 1.23.4
- Kieback & Peter DDC4100: up to and including 1.12.14
- Kieback & Peter DDC4200: up to and including 1.12.14
- Kieback & Peter DDC4200-L: up to and including 1.12.14
- Kieback & Peter DDC4200E: up to and including 1.23.4
- Kieback & Peter DDC4400: up to and including 1.12.14
- Kieback & Peter DDC4400E: up to and including 1.23.4
- Kieback & Peter DDC520: up to and including 1.24.1
Published 2026-05-20. Last modified 2026-07-23.