Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Frostbyte10 Vulnerabilities Let Hackers Gain Remote Access

Armis Labs has identified ten critical security vulnerabilities, collectively termed "Frostbyte10," in Copeland's E2 and E3 building management controllers. These devices, responsible for managing refrigeration, HVAC, lighting, and other key functions,…

Armis Labs has identified ten critical security vulnerabilities, collectively termed "Frostbyte10," in Copeland's E2 and E3 building management controllers. These devices, responsible for managing refrigeration, HVAC, lighting, and other key functions, are susceptible to remote code execution, settings alteration, system disablement, and data theft.

A firmware update is currently available, and affected organizations are strongly advised to apply it immediately.

Copeland's E2 and E3 controllers are extensively utilized in sectors such as retail, cold-chain logistics, and critical infrastructure. Both the E2 platform, which is now end-of-life, and the newer E3 system possess vulnerabilities that can be exploited together to achieve full, unauthenticated root access.

Potential attacks include manipulating temperatures, shutting down refrigeration units, and disabling emergency lighting, which could jeopardize food safety, supply chains, and human safety.

A firmware update is currently available, and affected organizations are strongly advised to apply it immediately.
Brooke Sanders · Thehackingpost

Armis Labs collaborated with Copeland to examine these vulnerabilities, assess their implications, and develop appropriate patches. Firmware version 2.31F01 for E3 devices and corresponding updates for E2 controllers address all ten identified vulnerabilities and must be installed promptly.

Organizations using E2 controllers should plan to transition to the E3 platform, as support for the E2 ended in October 2024.

CVE-2025-6519: Predictable generation of default admin password "ONEDAY" (Critical, CVSS 9.3) CVE-2025-52543: Authentication bypass using only the password hash (Medium, CVSS 5.3) CVE-2025-52544: Unauthenticated arbitrary file read via crafted floor plan upload (High, CVSS 8.8) CVE-2025-52545: Privilege escalation through exposed API revealing user hashes (High, CVSS 7.7) CVE-2025-52546: Stored cross-site scripting (XSS) via floor plan upload (Medium, CVSS 5.1) CVE-2025-52547: Denial-of-service by crashing application services through invalid input (High, CVSS 8.7) CVE-2025-52548: Hidden API enables SSH and Shellinabox for remote OS access (Medium, CVSS 6.9) CVE-2025-52549: Predictable root Linux password generation on each boot (Critical, CVSS 9.2) CVE-2025-52550: Unsigned firmware upgrade packages allow malicious firmware installation (High, CVSS 8.6) CVE-2025-52551: Unauthenticated proprietary protocol permits arbitrary file operations on E2 controllers (Critical, CVSS 9.3)

Advertisement

Apply Firmware Updates: Upgrade E3 controllers to version 2.31F01 or later. E2 customers should migrate and update as soon as possible. Network Segmentation: Isolate controllers on separate networks with strict firewall rules. Strong Authentication: Replace default accounts, enforce strong passwords, and disable unused remote access features. Continuous Monitoring: Implement vulnerability scanning and monitor logs for unusual activity. Incident Response Planning: Develop and test plans to detect, contain, and recover from attacks. Employee Training: Educate staff on cybersecurity risks and safe practices. Vendor Collaboration: Work with security researchers and vendors for timely threat intelligence and updates.

By implementing these measures and installing the patched firmware, organizations can mitigate the Frostbyte10 attack vector and safeguard critical infrastructure from remote threats.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories