← Back

Wire · regulatory

Active Attacks on KNX Smart Building Protocol Leave Hardware Permanently Bricked

Published

20 July 2026

Topic

regulatory

Sectors

Smart BuildingsCybersecurity

Geography

Europe

Source

Read at techtimes.com

Verified

Fusion42 · 20 July 2026 · Fusion42 review

A five-year-old KNX smart building protocol vulnerability (CVE-2023-4346) allows attackers to permanently brick building automation hardware by setting an irreversible password lock and wiping device firmware. CISA added it to its Known Exploited Vulnerabilities catalog on 15 July 2026, triggering a federal mitigation deadline, but the flaw affects 172 countries and hundreds of millions of devices globally with no factory reset path available.

This Wire brief sits within Fusion42's coverage of Smart Buildings and Cybersecurity.

◆ The Wire takeaway

If you're selling anything that plugs into or controls a KNX network — sensors, actuators, gateways, or integration software — your installed base is now a known target for permanent hardware destruction, and your customers have no way to recover. You need to ship a reset path or a network isolation product this month, or your support queue will become a liability.

Coverage

1 source · 20 Jul 2026

Related on Wire

Topics

Smart BuildingsCybersecurityknx-protocolhardware-brickingbuilding-automationzero-mitigationsupply-chain-vulnerability