CVE-2026-78319: Sauter ECOS504

Critical severity, CVSS 9.3. EPSS: 0.6% chance of exploitation in the next 30 days.

A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this race condition to bypass intended security controls. This may result in the execution of unauthorized code.

Affected products

  • Sauter ECOS504: from 1.0.0, before 7.0.0 (fixed in 7.0.0)
  • Sauter ECOS505: from 1.0.0, before 7.0.0 (fixed in 7.0.0)
  • Sauter MODU612-Lc: from 1.0.0, before 4.0.0 (fixed in 4.0.0)
  • Sauter MODU660-As: from 1.0.0, before 4.0.0 (fixed in 4.0.0)
  • Sauter MODU680-As: from 1.0.0, before 4.0.0 (fixed in 4.0.0)

Published 2026-09-01. Last modified 2026-09-03.