Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2019, Trend Micro researchers reported security weaknesses in radio remote controllers for industrial applications, including equipment used to operate cranes. Their tests demonstrated attacks against devices from seven popular vendors, but the findings do not show that every crane—or every controller in use today—is vulnerable. A separately documented flaw, CVE-2018-17935, applies specifically to Telecrane F25 Series controls before version 00.0A.

What the 2019 crane remote-control research found

Industrial radio remote controllers send commands to machinery such as cranes. In January 2019, Trend Micro Research published A Security Analysis of Radio Remote Controllers for Industrial Applications, describing in-lab and on-site analysis of equipment from seven popular vendors. The researchers reported several weaknesses that could let an attacker interfere with command handling or controller configuration.

The report describes demonstrations involving cranes in construction, factory, and transportation environments. The researchers wrote: “In all of the cases, we were able to switch on the controlled industrial machine even after the operator had issued an e-stop.” That statement refers to their test cases, not to every crane or every emergency-stop system.

A related paper, A Security Evaluation of Industrial Radio Remote Controllers, appeared in June 2019. Its abstract describes five practical attacks affecting major vendors and multiple real-world installations. It also says responsible disclosure led to first security patches and increased awareness. That historical account does not establish the current patch status of every vendor, product, or installation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How attacks on industrial radio remotes can work

The report describes several attack classes. Their feasibility depends on the particular controller and circumstances; the study does not establish that every device supports every attack.

Attack class What it means What the sources establish
Replay An attacker records a valid radio command and transmits it again. NVD documents a fixed-code replay weakness for Telecrane F25 Series controls before 00.0A in CVE-2018-17935.
Command spoofing or injection A weakness in command validation may allow a forged command to be accepted. Trend Micro describes command attacks among the weaknesses found in the systems it studied.
Emergency-stop abuse An attack interferes with stop behavior or the machine’s response to it. Trend Micro reported that in its tested cases, machinery could be switched on after an operator issued an e-stop.
Malicious re-pairing An attacker exploits weaknesses in how a transmitter and receiver are paired. Trend Micro identifies re-pairing weaknesses as an attack class; the cited material does not give a universal product or version range.
Programming-path compromise An attacker compromises software or a computer used to program a controller, potentially enabling persistent firmware changes. Trend Micro warns that some programming software may lack security measures. The relevant exposure depends on the specific programming setup.

SecurityWeek also summarized a research scenario involving a small, battery-powered device placed within radio range that could relay an attack over the internet. This is a reported relay scenario; it does not mean an internet attacker can directly reach every crane’s radio link.

What CVE-2018-17935 says about Telecrane F25 controls

CVE-2018-17935 is a specific example, separate from the broader Trend Micro study. The National Vulnerability Database (NVD) describes the affected products as Telecrane F25 Series radio controls before version 00.0A. Its record says those controls “use fixed codes that are reproducible by sniffing and re-transmission.” In practical terms, the documented weakness allows a captured command to be replayed; NVD also describes possible command spoofing or keeping the controlled load in a permanent stop state.

NVD displays a CVSS 3.1 score of 8.1, rated high, for this CVE. That score belongs to the Telecrane vulnerability record. It is not a severity score for every issue in the Trend Micro research or for all industrial radio remotes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the findings do—and do not—say about current equipment

The work is from 2019. It shows that researchers found and demonstrated weaknesses in the equipment they studied; it does not establish that all crane remote controls are vulnerable, that a particular product remains unpatched, or that newer equipment has the same flaw. The conference paper’s account of initial patches likewise does not identify the present status of every model and version.

Trend Micro’s study scope was seven popular vendors, a count of the vendors analyzed—not a measure of what share of the market is vulnerable. No current, independently established count of vulnerable crane controllers is established by these sources. Avoid treating the report’s phrase “millions of vulnerable units” as a present-day inventory.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What equipment owners should do

Organizations operating cranes or other machinery controlled by radio remotes should treat the controller as part of the safety-critical control system. Start by identifying the exact equipment and configuration, then seek guidance for that specific setup.

  1. Inventory the system: Record the controller manufacturer, exact model, transmitter and receiver pairing, and available firmware or version information.
  2. Contact the manufacturer: Ask for current security guidance, affected-version information, and applicable patches or mitigations for the exact model and configuration.
  3. Get qualified help if needed: If the status or exposure is unclear, consult a qualified industrial control systems security assessor familiar with operational technology and the machinery involved.

Do not infer that a device is safe or vulnerable from its brand alone. The 2019 study does not provide a complete, current product-by-product comparison, and a mitigation for one model should not be assumed to apply to another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.