Two of the most widely deployed supervisory controllers in commercial refrigeration carried vulnerabilities that would let an attacker manipulate cooling equipment while the system continued to report normal temperatures, according to research by industrial cyber security firm, Claroty.
Claroty’s Team82 researchers discovered the vulnerabilities in two popular refrigeration controller platforms commonly used in the food and beverage sector – the Danfoss AK-SM 800A and Copeland XWEB Pro. Both manufacturers have since released firmware addressing the flaws.
These supervisory controllers are responsible for coordinating refrigeration equipment and ensuring stable operations, and are commonly used in supermarkets, cold storage facilities, warehouses, and other commercial environments.
The vulnerabilities compromise the systems by allowing attackers to physically manipulate refrigeration systems while the interface kept displaying expected readings, allowing stock to spoil without triggering an alarm or leaving a record.
These vulnerabilities present a significant risk for Australian businesses, given modern cold-chain logistics depend on precise, uninterrupted climate control. Large distribution centres store tonnes of perishable food, while supermarkets operate extensive refrigerated display networks, and healthcare facilities safeguard temperature-sensitive pharmaceuticals.
More broadly, these findings underscore the need for stronger cybersecurity across the commercial refrigeration industry. Predictable credentials, Internet-exposed management interfaces, and slow adoption of firmware updates continue to leave critical systems vulnerable.
Improving resilience in the industry requires timely patching, network segmentation, restricting Internet exposure, and securing the supervisory controllers at the centre of these environments.
Danfoss AK-SM 800A vulnerabilities
Danfoss is one of the largest manufacturers of refrigeration and HVAC equipment worldwide. Its solutions are deployed throughout supermarkets, cold-storage facilities, warehouses, and commercial buildings.
Among its management platforms is the AK-SM 800A, a centralised system manager responsible for coordinating refrigeration controllers throughout an installation.
The platform aggregates information from numerous field devices while providing operators with a web-based management interface for monitoring and configuring the entire refrigeration environment. The system effectively becomes the operational control centre for Danfoss refrigeration infrastructure.
Because these systems provide centralised management of refrigeration equipment, compromising the management interface can have significant operational consequences.
Team82 researched the attack surface of the Danfoss AK-SM 800A platform and identified three vulnerabilities affecting the embedded web management interface. Notably, Claroty uncovered a hidden ‘code-of-the-day’ authentication mechanism (CVE-2025-41450) that could be abused to bypass normal authentication, leading to remote code execution.
Claroty Team82 privately reported these vulnerabilities to Danfoss through a coordinated vulnerability disclosure process. Danfoss investigated the findings and released firmware version R4.3.1, which addresses the vulnerabilities.
Customers using affected AK-SM 800A controllers should upgrade to firmware version R4.3.1 or later as soon as possible.
Organisations should also avoid exposing management interfaces directly to the Internet and ensure that access to administrative services is restricted to trusted management networks or secured through VPNs and other appropriate network segmentation controls.
For the full list of the vulnerabilities, click here for the report.
Copeland XWEB Pro platform vulnerabilities
Team82 also researched the attack surface of the Copeland XWEB Pro platform to assess its resilience against network-based attacks. Copeland XWEB Pro is one of the most widely-deployed controllers for commercial refrigeration, air-conditioning, and food retail applications.
These controllers manage distributed field devices, coordinating compressors, evaporators, and environmental sensors while maintaining the temperature records required for regulatory compliance.
Claroty’s analysis uncovered a total of 23 vulnerabilities in the platform, 21 of which are high-severity.
Each issue independently poses a significant security risk and can ultimately allow an unauthenticated attacker to progressively bypass the platform's security mechanisms, resulting in root-level remote code execution (RCE).
These controllers play a critical role in monitoring and controlling refrigeration equipment that protects temperature-sensitive goods and infrastructure. These vulnerabilities allow an attacker to compromise the platform, bypass its security controls, and influence connected field devices responsible for critical refrigeration operations.
Claroty disclosed the vulnerabilities to Copeland, which successfully patched these vulnerabilities and has uploaded firmware update version 1.13 to secure affected XWEB Pro devices.
For a full breakdown of the vulnerabilities, click here for the report.
