A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.
Trane has released the following versions of Tracer SC+ for users to upgrade to:
- CVE-2026-28252: Tracer SC+ version v6.30.2313