rootpwn

critical · CVSS v3 9.8 · CVSS v4 7.2

CVE-2026-71448

Johnson Controls EasyIO FS32 devices prior to version 3.0b63 are vulnerable to insecure default initialization of resources, enabling attack

Overview

Johnson Controls EasyIO FS32 devices prior to version 3.0b63 are vulnerable to insecure default initialization of resources, enabling attackers to abuse authentication mechanisms. This flaw can allow unauthorized access to the device's control interface. The vulnerability is rated critical with a CVSS v3 score of 9.8.

Description

: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63.

Impact

The vulnerability compromises confidentiality, integrity, and availability of the device's control functions. Attackers can gain unauthorized access, potentially manipulating HVAC or building automation settings. Defenders should treat exposed devices as compromised until patched. The risk is high for facilities relying on these controllers.

Remediation

Update the device firmware to version 3.0b63 or later, which removes the insecure default initialization. If an update is not immediately possible, disable unused authentication methods, enforce strong passwords, and restrict network access to the device via firewalls or VLAN segmentation. Monitor device logs for anomalous authentication attempts.

Risk context

Critical severity and a CVSS v3 score of 9.8 indicate a high risk. No EPSS data is available, but the lack of a patch for older firmware increases urgency. Defenders should prioritize remediation.

Affected products

  • Johnson Controls EasyIO FS32

Scores

Severity
critical
CVSS v2
6.4
CVSS v3
9.8
CVSS v4
7.2
EPSS
—

authentication firmware critical Johnson Controls EasyIO resource-initialization device-security

← All CVEs