device library

AERCO BMS/C-More boiler controller

Register map(s) for this device, with a note of how far each has been checked. Addresses are 0-based, as on the wire. Scale and byte order are confirmed only at the hardware-verified rung.

coherence-checked

Round-trips through a real Modbus stack with no overlapping addresses and a word-order-sensitive codec — the map is internally coherent and wire-decodable. Does NOT prove byte-order or scaling match a real device: the emulator is seeded from the map's own types, so a uniformly wrong byte-order still round-trips. Only hardware-verified confirms byte-order/scale on the wire.

pointaddress (0-based)typescaleunit
Net Remote Set Point0U161
Default Message Display Code0U161
Net Direct Drive1U161%
Unit Status1U161
Modbus Password2U161
Outlet Temp2U161
Password3U161
Inlet Temp3U161
Internal Set Point4U161
Aux Temp4U161
Outdoor Temp5U161
Time6U161
Exhaust Temp6U161
Date7U161
FFWD Temp7U161
Unit of Temp8U161
Fire Rate Out8U161%
Baud Rate9U161
O2 Level9U161%
Unit Type10U161
CO Level10U161PPM
Unit Size11U161
Run Cycles Low (LSB)11U161
Boiler Mode12U161
Run Cycles High (MSB)12U161
Remote Signal13U161
Run Hours Low (LSB)13U161
Bldg Ref Temp14U161
Run Hours High (MSB)14U161
Reset Ratio15U161
Flame Strength15U161%
Outdoor Sensor Enable16U161
Active Set point16U161
System Start Temp17U161
Fire Rate In17U161%
Set Point Lo Limit18U161
Manual Fire Rate18U161%
Set Point Hi Limit19U161
Comm Address19U161
Temp Hi Limit20U161
Software Version20U161
Max Fire Rate21U161%
Pump Delay Timer22U161MIN_UNITS
C-More: Fault Log Code23U161
C-More: Fault Log Cycle (LOW)24U161
C-More: Fault Log Cycle (HIGH)25U161
C-More: Fault Log Date26U161
C-More: Fault Log Time27U161
C-More: Sensor Log Active Setpoint28U161DEGREES_1
C-More: Sensor Log Outlet Temp29U161DEGREES_1
C-More: Sensor Log Inlet Temp30U161DEGREES_1
C-More: Sensor Log FFWD Temp31U161DEGREES_1
C-More: Sensor Log Exhaust Temp32U161DEGREES_3
C-More: Sensor Log Outdoor Temp33U161DEGREES_2
C-More: Sensor Log Aux Temp34U161DEGREES_1
C-More: Sensor Log CO xmitter35U161PPM_UNITS
C-More: Sensor Log O2 xmitter36U161%
C-More: Sensor Log Flow Meter37U161GPM_UNITS
C-More: Time Log Status38U161
C-More: Time Log Fire Rate39U161%
C-More: Time Log Flame Strength40U161%
C-More: Time Log Run Length41U161
C-More: Time Log Date42U161
C-More: Time Log Time43U161
BMS: Boiler 28 Status (BMS) / Boiler 20 Status (BMS II)44U161
BMS: Boiler 29 Status (BMS) / Boiler 21 Status (BMS II)45U161
BMS: Boiler 30 Status (BMS) / Boiler 22 Status (BMS II)46U161
BMS: Boiler 31 Status (BMS) / Boiler 23 Status (BMS II)47U161
BMS: Boiler 32 Status (BMS) / Boiler 24 Status (BMS II)48U161
BMS: Boiler 33 Status (BMS) / Boiler 25 Status (BMS II)49U161
BMS: Boiler 34 Status (BMS) / Boiler 26 Status (BMS II)50U161
BMS: Boiler 35 Status (BMS) / Boiler 27 Status (BMS II)51U161
BMS: Boiler 36 Status (BMS) / Boiler 28 Status (BMS II)52U161
BMS: Boiler 37 Status (BMS) / Boiler 29 Status (BMS II)53U161
BMS: Boiler 38 Status (BMS) / Boiler 30 Status (BMS II)54U161
BMS: Boiler 39 Status (BMS) / Boiler 31 Status (BMS II)55U161
BMS: Boiler 40 Status (BMS) / Boiler 32 Status (BMS II)56U161
BMS: I/O Status57U161
BMS: Return Sensor Temp58U161°F
BMS: Offset Enable59U161
C-More: Set Point Limiting60U161
C-More: Set Point Limit Band61U161ABS_DEG_1
C-More: Sensor Log Interval67U161
C-More: Fault Log Pointer68U161
C-More: Sensor Log Pointer69U161
C-More: Time Log Pointer70U161
BMS: Offset Off Time Day 2 - Minutes71U161Minutes
BMS: Offset Off Time Day 3 - Minutes72U161Minutes
BMS: Offset Off Time Day 4 - Minutes73U161Minutes
BMS: Offset Off Time Day 5 - Minutes74U161Minutes
BMS: Offset Off Time Day 6 - Minutes75U161Minutes
BMS: Offset Off Time Day 7 - Minutes76U161Minutes
BMS: Offset Off Time Day 1 - Hours77U161Hours
BMS: Offset Off Time Day 2 - Hours78U161Hours
BMS: Offset Off Time Day 3 - Hours79U161Hours
BMS: Offset Off Time Day 4 - Hours80U161Hours
BMS: Offset Off Time Day 5 - Hours81U161Hours
BMS: Offset Off Time Day 6 - Hours82U161Hours
BMS: Offset Off Time Day 7 - Hours83U161Hours
BMS: Indoor Air Input85U161
BMS: Remote Signal86U161
BMS: RS232 Mode87U161
BMS: RS232 Baud Rate88U161
BMS: Number Of Network Boilers89U161
BMS: Min Slave Address90U161
BMS: Max Slave Address91U161
BMS: Net Boiler 1 Address92U161
BMS: Net Boiler 2 Address93U161
BMS: Net Boiler 3 Address94U161
BMS: Net Boiler 4 Address95U161
BMS: Net Boiler 5 Address96U161
BMS: Net Boiler 6 Address97U161
BMS: Net Boiler 7 Address98U161
BMS: Net Boiler 8 Address99U161
BMS: Net Boiler 9 Address100U161
BMS: Net Boiler 10 Address101U161
BMS: Net Boiler 11address102U161
BMS: Net Boiler 12 Address103U161
BMS: Net Boiler 13 Address104U161
BMS: Net Boiler 14 Address105U161
BMS: Net Boiler 15 Address106U161
BMS: Net Boiler 16 Address107U161
BMS: Net Boiler 17 Address108U161
BMS: Net Boiler 18 Address109U161
BMS: Net Boiler 19 Address110U161
BMS: Net Boiler 20 Address111U161
BMS: Net Boiler 21 Address112U161
BMS: Net Boiler 22 Address113U161
BMS: Net Boiler 23 Address114U161
BMS: Net Boiler 24 Address115U161
BMS: Net Boiler 25 Address116U161
BMS: Net Boiler 26 Address117U161
BMS: Net Boiler 27 Address118U161
BMS: Net Boiler 28 Address119U161
BMS: Net Boiler 29 Address120U161
BMS: Net Boiler 30 Address121U161
BMS: Net Boiler 31 Address122U161
BMS: Net Boiler 32 Address123U161
BMS: Network Baud124U161
BMS: Network Timeout125U161sec
BMS: Password Lo126U161
BMS: Password Hi127U161
BMS: Modbus Control Type128U161
BMS: Modbus Pass-Thru129U161
BMS: Header Dead Band130U161°F
BMS: Outside Temp Sensor Offset131I161°F
BMS: Ramp Up %/MIN132U161
BMS: Ramp Down %/MIN133U161
BMS: Fault Alarm Boilers134U161
BMS: 4 to 20 mA Current Offset135I160.01mA
BMS: Return Sensor Offset136I160.1
BMS: Load Start Pct137U161
BMS: Load Stop Pct138U161

link settings as documented (unverified): RTU; default 9600 8??; unit ID 128; FC 03,04,06,08,17; RTU transmission ONLY. C-More baud rate is fixed at 9600.

bench facts as documented (unverified)
terminalsRS485, 2-Wire Differential Bus With Shield
A/B polarityIt is imperative that polarity be maintained between all Modbus Network connections.
terminationA terminating resistor (120 ohms) on each end of the RS485 loop. BMS/BMS II has a built-in 120 ohm terminating resistor.
connectorRS232 (DB9-Female) and internal RS232 connector
isolation232 ISO GND
shield/groundtwisted-pair wiring shield should only be terminated at the controlling Master Controller for the Modbus Network.
broadcastsupported
protocol notesHeartbeat Timeout: Fixed at 10 seconds For C-More, Adjustable For BMS/BMS II: 5 to 240 Seconds
firmware register20
FC 43 device IDnot supported
power85-265 VAC
doc revisionREVISED FEBRUARY 17, 2011
field reports — community-sourced, unverified (checked 2026-06-11)
  • confirmed: comms defaults (baud rate 9600, default unit ID 128, RTU framing) — confirmed by AERCO Modbus Communication User Manual OMM-0035 (GF-114)
  • confirmed: physical layer (RS485 2-wire differential bus, 120 ohm termination, RS232 DB9 connector) — confirmed by AERCO Modbus Guidelines GF-2080 and OMM-0035
  • confirmed: register map summary (default_message_display_code @ 0, unit_status @ 1, outlet_temp @ 2, inlet_temp @ 3, aux_temp @ 4, outdoor_temp @ 5, exhaust_temp @ 6, ffwd_temp @ 7, fire_rate_out @ 8, o2_level @ 9, co_level @ 10, run_cycles_low @ 11, run_cycles_high @ 12, run_hours_low @ 13, run_hours_high @ 14, flame_strength @ 15, active_setpoint @ 16, fire_rate_in @ 17, manual_fire_rate @ 18) — confirmed by AERCO Modbus Communication User Manual OMM-0035 (GF-114) Standard Input Register Address Mapping

The trust ladder

Each rung states what it proved and what it did not. Gray until proven; green is earned by hardware only.

Device not here? Upload its manual and get a checked map back. It's free.

Want it confirmed against your own device? Order hardware verification. If it doesn't check out, you don't pay.

Building on a lot of devices? License the library — machine-readable maps, the firmware matrix, and API access.