A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
References
| Link | Resource |
|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-01 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2026-03-12 18:16
Updated : 2026-03-27 16:25
NVD link : CVE-2026-28255
Mitre link : CVE-2026-28255
CVE.ORG link : CVE-2026-28255
JSON object : View
Products Affected
trane
- tracer_concierge
- tracer_sc\+
- tracer_sc\+_firmware
- tracer_sc
- tracer_sc_firmware
CWE
CWE-798
Use of Hard-coded Credentials
