CVE-2026-78319
Received Received - Intake

Time-of-Check Time-of-Use Race Condition in Product

Vulnerability report for CVE-2026-78319, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: CERT VDE

Description

A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this race condition to bypass intended security controls. This may result in the execution of unauthorized code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
sauter ey_rc504f to 7.0.0 (exc)
sauter ey_rc505f to 7.0.0 (exc)
sauter ey6lc12f011 to 4.0.0 (exc)
sauter ey6as60f011 to 4.0.0 (exc)
sauter ey6as80f021 to 4.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-78319 is a Time-of-Check Time-of-Use (TOCTOU) race condition in SAUTER Building Controllers. This flaw allows unauthenticated remote attackers to bypass security controls and execute unauthorized code by exploiting timing discrepancies in the firmware update mechanism.

Detection Guidance

Detecting this TOCTOU vulnerability requires checking firmware versions of SAUTER Building Controllers. Use network scanning tools to identify affected devices (EY-RC504F, EY-RC505F, EY6LC12F011, EY6AS60F011, EY6AS80F021) and verify if they run ecos504, ecos505, or modulo 6 software below 7.0.0 or 4.0.0 respectively.

Impact Analysis

Exploitation could grant full control over affected devices, potentially compromising building automation functions. This may lead to unauthorized access, device manipulation, or disruption of critical building systems.

Compliance Impact

The TOCTOU vulnerability in SAUTER Building Controllers could allow unauthorized code execution, potentially compromising building automation functions. This may lead to unauthorized access to sensitive data processed by these systems, which could impact compliance with GDPR (data protection) and HIPAA (healthcare data security) if such data is handled by the affected devices.

Mitigation Strategies

Immediately update firmware to version 7.0.0 or newer for ecos504 and ecos505, and version 4.0.0 or newer for modulo 6 controllers. Ensure downgrade protection is enabled during updates to prevent rollback to vulnerable versions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78319. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart