Skip to content
devwallssecurity
An access controller on a metal door, its indicator lit red
research / DW-2026-011

Unverified firmware updates on a building access controller

The controller accepted firmware images without verifying a signature, allowing anyone with network access to the management interface to install persistent code on a device that opens doors.

affected
Door access controller, firmware below 2.9
cvss v3.1
9.1
published
2026-11-27
status
Patched — end-of-life models unfixed
critical
detail

The update endpoint checked a CRC and nothing else. We wrote an image that kept the device fully functional, unlocked a nominated door on a schedule, and survived a factory reset.

The vendor shipped signed updates in 2.9 for current models. Two discontinued models remain unfixed and are still widely deployed. If you operate them, the only reliable mitigation is network isolation of the management interface.

We are publishing this in full because the affected devices are physically accessible in public buildings and the mitigation is entirely within an operator's control.

timeline
  1. 2026-06-30
    Discovered during physical red team engagement
  2. 2026-07-03
    Reported to vendor
  3. 2026-09-15
    Signed firmware shipped for current models
  4. 2026-11-27
    Public disclosure, end-of-life models unfixed
backall advisories
A dense city skyline at night, lit windows in red and amber

worried this affects you

If you run the affected product and are not sure whether you are exposed, send us the version and configuration. We will tell you, and there is no charge for that answer.