
Yo @Trane_Tech @TraneCommercial 2026 and your Tracer SC+ controllers are still getting left exposed with zero auth on oBIX and known RCEs (CVE-2021-38450). Found one controlling an entire commercial HVAC setup. ISP notified too. These are physical building systems, not toys. Get them off the open internet. #OTSecurity #Hacking #ResponsibleDisclosure
Post summary
The tweet discloses that Tracer SC+ controllers remain exposed with zero authentication on oBIX, enabling remote code execution via CVE-2021-38450, and reports finding an exposed device controlling a commercial HVAC system, urging removal from the internet.
