critical · CVSS v3 9.8 · CVSS v4 7.2
CVE-2026-71448
Johnson Controls EasyIO FS32 devices prior to version 3.0b63 are vulnerable to insecure default initialization of resources, enabling attack
Overview
Johnson Controls EasyIO FS32 devices prior to version 3.0b63 are vulnerable to insecure default initialization of resources, enabling attackers to abuse authentication mechanisms. This flaw can allow unauthorized access to the device's control interface. The vulnerability is rated critical with a CVSS v3 score of 9.8.
Description
: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63.
Impact
The vulnerability compromises confidentiality, integrity, and availability of the device's control functions. Attackers can gain unauthorized access, potentially manipulating HVAC or building automation settings. Defenders should treat exposed devices as compromised until patched. The risk is high for facilities relying on these controllers.
Remediation
Update the device firmware to version 3.0b63 or later, which removes the insecure default initialization. If an update is not immediately possible, disable unused authentication methods, enforce strong passwords, and restrict network access to the device via firewalls or VLAN segmentation. Monitor device logs for anomalous authentication attempts.
Risk context
Critical severity and a CVSS v3 score of 9.8 indicate a high risk. No EPSS data is available, but the lack of a patch for older firmware increases urgency. Defenders should prioritize remediation.
Affected products
- Johnson Controls EasyIO FS32
Scores
- Severity
- critical
- CVSS v2
- 6.4
- CVSS v3
- 9.8
- CVSS v4
- 7.2
- EPSS
- —