CVE-2025-13926 – Contemporary Controls BASControl20

CVSS 9.8 CRITICAL

“A single exposed weakness can open the door to full system compromise.”

This patch addresses a critical vulnerability in Contemporary Controls BASControl20 devices that could allow an attacker to gain unauthorized control over the system. The issue poses a severe risk to building automation environments, where these controllers are often deployed to manage HVAC and other infrastructure systems.

CVE-2025-13926 has a CVSS score of 9.8, which is Critical severity. This level of severity indicates that the vulnerability can be exploited remotely with little to no user interaction, potentially leading to full system compromise. No verified exploitation or proof-of-concept activity has been confirmed at this time.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-807
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.