Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallIn 2019, Trend Micro researchers reported security weaknesses in radio remote controllers for industrial applications, including equipment used to operate cranes. Their tests demonstrated attacks against devices from seven popular vendors, but the findings do not show that every crane—or every controller in use today—is vulnerable. A separately documented flaw, CVE-2018-17935, applies specifically to Telecrane F25 Series controls before version 00.0A.
What the 2019 crane remote-control research found
Industrial radio remote controllers send commands to machinery such as cranes. In January 2019, Trend Micro Research published A Security Analysis of Radio Remote Controllers for Industrial Applications, describing in-lab and on-site analysis of equipment from seven popular vendors. The researchers reported several weaknesses that could let an attacker interfere with command handling or controller configuration.
The report describes demonstrations involving cranes in construction, factory, and transportation environments. The researchers wrote: “In all of the cases, we were able to switch on the controlled industrial machine even after the operator had issued an e-stop.” That statement refers to their test cases, not to every crane or every emergency-stop system.
A related paper, A Security Evaluation of Industrial Radio Remote Controllers, appeared in June 2019. Its abstract describes five practical attacks affecting major vendors and multiple real-world installations. It also says responsible disclosure led to first security patches and increased awareness. That historical account does not establish the current patch status of every vendor, product, or installation.
#1 Best Overall
How attacks on industrial radio remotes can work
The report describes several attack classes. Their feasibility depends on the particular controller and circumstances; the study does not establish that every device supports every attack.
| Attack class | What it means | What the sources establish |
|---|---|---|
| Replay | An attacker records a valid radio command and transmits it again. | NVD documents a fixed-code replay weakness for Telecrane F25 Series controls before 00.0A in CVE-2018-17935. |
| Command spoofing or injection | A weakness in command validation may allow a forged command to be accepted. | Trend Micro describes command attacks among the weaknesses found in the systems it studied. |
| Emergency-stop abuse | An attack interferes with stop behavior or the machine’s response to it. | Trend Micro reported that in its tested cases, machinery could be switched on after an operator issued an e-stop. |
| Malicious re-pairing | An attacker exploits weaknesses in how a transmitter and receiver are paired. | Trend Micro identifies re-pairing weaknesses as an attack class; the cited material does not give a universal product or version range. |
| Programming-path compromise | An attacker compromises software or a computer used to program a controller, potentially enabling persistent firmware changes. | Trend Micro warns that some programming software may lack security measures. The relevant exposure depends on the specific programming setup. |
SecurityWeek also summarized a research scenario involving a small, battery-powered device placed within radio range that could relay an attack over the internet. This is a reported relay scenario; it does not mean an internet attacker can directly reach every crane’s radio link.
Rank #2
What CVE-2018-17935 says about Telecrane F25 controls
CVE-2018-17935 is a specific example, separate from the broader Trend Micro study. The National Vulnerability Database (NVD) describes the affected products as Telecrane F25 Series radio controls before version 00.0A. Its record says those controls “use fixed codes that are reproducible by sniffing and re-transmission.” In practical terms, the documented weakness allows a captured command to be replayed; NVD also describes possible command spoofing or keeping the controlled load in a permanent stop state.
NVD displays a CVSS 3.1 score of 8.1, rated high, for this CVE. That score belongs to the Telecrane vulnerability record. It is not a severity score for every issue in the Trend Micro research or for all industrial radio remotes.
What the findings do—and do not—say about current equipment
The work is from 2019. It shows that researchers found and demonstrated weaknesses in the equipment they studied; it does not establish that all crane remote controls are vulnerable, that a particular product remains unpatched, or that newer equipment has the same flaw. The conference paper’s account of initial patches likewise does not identify the present status of every model and version.
Trend Micro’s study scope was seven popular vendors, a count of the vendors analyzed—not a measure of what share of the market is vulnerable. No current, independently established count of vulnerable crane controllers is established by these sources. Avoid treating the report’s phrase “millions of vulnerable units” as a present-day inventory.
Rank #4
What equipment owners should do
Organizations operating cranes or other machinery controlled by radio remotes should treat the controller as part of the safety-critical control system. Start by identifying the exact equipment and configuration, then seek guidance for that specific setup.
- Inventory the system: Record the controller manufacturer, exact model, transmitter and receiver pairing, and available firmware or version information.
- Contact the manufacturer: Ask for current security guidance, affected-version information, and applicable patches or mitigations for the exact model and configuration.
- Get qualified help if needed: If the status or exposure is unclear, consult a qualified industrial control systems security assessor familiar with operational technology and the machinery involved.
Do not infer that a device is safe or vulnerable from its brand alone. The 2019 study does not provide a complete, current product-by-product comparison, and a mitigation for one model should not be assumed to apply to another.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

