rootpwn

critical · CVSS v3 7.5 · CVSS v4 10

CVE-2026-71449

Johnson Controls EasyIO FS32 devices before 3.0b63 contain a hard‑coded cryptographic key that can be exploited to retrieve embedded sensiti

Overview

Johnson Controls EasyIO FS32 devices before 3.0b63 contain a hard‑coded cryptographic key that can be exploited to retrieve embedded sensitive data. The flaw allows attackers to read protected information from the device. It is a critical vulnerability with a CVSS v4 score of 10.0.

Description

: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.

Impact

Confidentiality is compromised as attackers can read sensitive data stored on the device. Availability may be impacted if the device is misused to exfiltrate data. Integrity is at risk if attackers modify data. Defenders and device operators are directly affected.

Remediation

Upgrade EasyIO FS32 to version 3.0b63 or later where the hard‑coded key issue is fixed. If upgrade is not possible, disable cryptographic functions that rely on the hard‑coded key or replace the key with a secure, device‑specific key. Apply any vendor security patches and monitor device logs for anomalous read attempts.

Risk context

The vulnerability is rated critical with a CVSS v4 score of 10.0, indicating a high likelihood of exploitation and severe impact. Immediate attention is warranted to mitigate potential data exposure.

Affected products

  • Johnson Controls EasyIO FS32
  • EasyIO FS32
  • Johnson Controls FS32

Scores

Severity
critical
CVSS v2
5
CVSS v3
7.5
CVSS v4
10
EPSS
—

hardcoded-key JohnsonControls EasyIO critical data-exfiltration patch vulnerability

← All CVEs