Zero-Day
Johnson Controls EasyIO FG
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873) CVSS Vendor E
CISA Alerts··3 min read
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873) CVSS Vendor Equipment v3 7.7 Johnson Controls EasyIO FG firmware 2 Vulnerabilities Use of Hard-coded Credentials, Improper Privilege Management Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27872 A vulnerability exists in EasyIO FG relating to an attacker gaining unauthorized access to the system through hard-coded credentials and improper privilege management, potentially resulting in full device compromise. Successful exploitation could result in technical or operational impact. Read More 1 Affected Product Johnson Controls EasyIO FG firmware: <=2.0b52 Product Status: known_affected Remediations Mitigation Johnson Controls has determined that the EasyIO FG Series has reached End-of-Life (EOL) and End-of-Support (EOS) status. The product has not been manufactured or sold since prior to 2019, and the source code is no longer available. As a result, no firmware patch or code-level fix will be issued. Users are advised to migrate to supported current-generation products (e.g., EasyIO Neo R1 Series). Mitigation Deploy devices only within isolated BAS/OT networks Mitigation Ensure no direct Internet exposure Mitigation Enforce strict VLAN segmentation from enterprise IT networks Mitigation Restrict access to trusted engineering workstations only Mitigation Block all remote login access from untrusted networks Mitigation Allow connections only from whitelisted IP addresses Mitigation Block all Internet-originated traffic Mitigation Prevent unauthorized lateral movement across networks Mitigation Restrict communication to required protocols only Mitigation Disable insecure services (e.g., Telnet), if enabled Mitigation Disable any unnecessary services or exposed ports Mitigation Monitor for repeated login attempts Mitigation Monitor for unauthorized or root-level access Mitigation Enable logging and centralized monitoring (where supported) Mitigation Restrict distribution of firmware images Mitigation Prevent unauthorized physical and console access Mitigation For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-12 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories Additional Metrics Relevant CWE: CWE-798 Use of Hard-coded Credentials CVSS Version Base Score Base Severity Vector String 3.1 7.7 HIGH CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H 4.0 7.2 HIGH CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H View CVE Details CVE-2026-27873 A vulnerability exists in EasyIO FG relating to an attacker gaining unauthorized access to the system through hard-coded credentials and improper privilege management, potentially resulting in full device compromise. Successful exploitation could result in technical or operational impact. Read More 2 Affected Products Johnson Controls EasyIO FG firmware: <=2.0b52 Product Status: known_affected Remediations Mitigation Johnson Controls has determined that the EasyIO FG Series has reached End-of-Life (EOL) and End-of-Support (EOS) status. The product has not been manufactured or sold since prior to 2019, and the source code is no longer available. As a result, no firmware patch or code-level fix will be issued. Users are advised to migrate to supported current-generation products (e.g., EasyIO Neo R1 Series). Mitigation Deploy devices only within isolated BAS/OT networks Mitigation Ensure no direct Internet exposure Mitigation Enforce strict VLAN segmentation from enterprise IT networks Mitigation