critical · CVSS v3 7.5 · CVSS v4 10
CVE-2026-71449
Johnson Controls EasyIO FS32 devices before 3.0b63 contain a hard‑coded cryptographic key that can be exploited to retrieve embedded sensiti
Overview
Johnson Controls EasyIO FS32 devices before 3.0b63 contain a hard‑coded cryptographic key that can be exploited to retrieve embedded sensitive data. The flaw allows attackers to read protected information from the device. It is a critical vulnerability with a CVSS v4 score of 10.0.
Description
: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.
Impact
Confidentiality is compromised as attackers can read sensitive data stored on the device. Availability may be impacted if the device is misused to exfiltrate data. Integrity is at risk if attackers modify data. Defenders and device operators are directly affected.
Remediation
Upgrade EasyIO FS32 to version 3.0b63 or later where the hard‑coded key issue is fixed. If upgrade is not possible, disable cryptographic functions that rely on the hard‑coded key or replace the key with a secure, device‑specific key. Apply any vendor security patches and monitor device logs for anomalous read attempts.
Risk context
The vulnerability is rated critical with a CVSS v4 score of 10.0, indicating a high likelihood of exploitation and severe impact. Immediate attention is warranted to mitigate potential data exposure.
Affected products
- Johnson Controls EasyIO FS32
- EasyIO FS32
- Johnson Controls FS32
Scores
- Severity
- critical
- CVSS v2
- 5
- CVSS v3
- 7.5
- CVSS v4
- 10
- EPSS
- —