Desigo Devices DoS via Malformed BACnet (v<01.21.233.16-7862)
CVE-2026-59693 Published on August 11, 2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.
Weakness Type
Improper Check for Unusual or Exceptional Conditions
The software does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the software.
Affected Versions
Siemens Desigo DXR2:- Before V01.21.233.16-7862 is affected.
- Before V01.21.233.16-7862 is affected.
- Before V02.21.194.36-2715 is affected.
- Before V02.21.194.36-2715 is affected.
- Before V02.21.194.36-2715 is affected.
- Before V02.21.194.36-2715 is affected.