External risk intelligence

Contemporary Controls BASC 20T Network Traffic Sniffing Allows Packet Forgery

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-13926

The product is an industrial building automation controller (Contemporary Controls BASC 20T). These devices are typically deployed within isolated operational technology or internal building management networks rather than being exposed directly to the public internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A network vulnerability exists that could allow an attacker to forge network traffic, potentially leading to unauthorized requests to a specific building automation controller. The primary concern is confirming whether this type of technology is in use and exposed within your environment.

  • Attackers can forge network requests to controllers.
  • Confirm relevance and exposure in your operational environment.
  • Understand potential risks to building automation systems.

Attack Path

How an attacker could exploit the issue

An attacker could intercept and modify network traffic to send malicious requests to the targeted device. This requires the attacker to be able to monitor network communications. The vulnerability in the Contemporary Controls BASC 20T could allow an attacker to execute arbitrary requests.

  • Network traffic sniffing is required.
  • Forge packets to make arbitrary requests.
  • Potentially severe impact on device operations.

Live Threat

Current exploitation, exposure, and threat context

Network traffic sniffing could allow an attacker to forge packets, enabling them to make arbitrary requests to the targeted system. This could affect the system's ability to correctly process legitimate requests, potentially leading to service disruption or unauthorized actions when supported by the advisory.

  • System requests could be forged.
  • Sniffed network traffic can be used.
  • Service behavior may be altered.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given the nature of the affected technology, a building automation controller, the primary responsibility likely lies with the infrastructure or operational technology (OT) teams managing these systems. The initial step should be to confirm the deployment of Contemporary Controls BASC 20T devices within the organization, assess their network exposure and criticality, identify the system owner, and then plan remediation or mitigation strategies accordingly.

  • Identify OT or infrastructure teams.
  • Confirm device presence and exposure.
  • Plan risk-based remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Contemporary Controls BASC 20T?

The BASC 20T is an industrial building automation controller. It is typically used to manage HVAC, lighting, and other mechanical systems within commercial buildings. These devices facilitate communication between sensors, actuators, and management platforms, acting as a bridge to ensure efficient operation of a facility's environmental systems.

What does CWE-807 mean in the context of CVE-2025-13926?

CWE-807 refers to a weakness where an application relies on untrusted inputs to make security decisions. In this specific CVE, the controller may incorrectly trust forged network packets. Because it does not sufficiently verify the authenticity of incoming requests, an attacker can trick the device into performing unauthorized actions as if the requests were legitimate.

How does an attacker trigger this vulnerability?

An attacker triggers this by first intercepting or sniffing network traffic to observe legitimate communications. Once they possess this data, they use it to create and inject forged packets into the network. Note that simply sending random, unformatted traffic at the device will not succeed; the attacker must have visibility into the network communication patterns to effectively masquerade as a valid requester.

Do I need to worry if my device is on an internal network?

Halo Surface Signal indicates that the BASC 20T is typically deployed within isolated operational technology or building management networks, making direct internet exposure unlikely. However, if an attacker gains a foothold on your internal network, they could still perform the necessary traffic sniffing. You should prioritize assets that are bridged or accessible from less secure network segments.

What are the first steps to address this CVE?

Start by identifying all instances of the Contemporary Controls BASC 20T within your environment by consulting your OT or infrastructure asset inventory. Once located, assess how these devices are networked. Coordinate with the system owners to confirm their criticality, review network segmentation to ensure they are isolated from unauthorized access, and prepare for updates or vendor-recommended configurations.

References