critical · CVSS v3 9.8 · CVSS v4 8.4
CVE-2026-71452
Johnson Controls EasyIO FS32 devices prior to version 3.0b63 are vulnerable to OS command injection, allowing attackers to execute arbitrary
Overview
Johnson Controls EasyIO FS32 devices prior to version 3.0b63 are vulnerable to OS command injection, allowing attackers to execute arbitrary shell commands. The flaw can be triggered via network interfaces exposed by the device. This vulnerability could compromise building automation systems and critical infrastructure.
Description
- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.
Impact
Confidentiality: attackers can read sensitive configuration and logs. Integrity: attackers can modify device settings or firmware. Availability: attackers can crash or lock out the device, disrupting building operations. Impacted parties include facility managers, network administrators, and building automation operators.
Remediation
Apply the latest firmware update (3.0b63 or newer) from Johnson Controls. If immediate update is not possible, restrict network access to the device using firewall rules or VLAN segmentation, and disable unused management interfaces. Monitor logs for suspicious command execution attempts.
Risk context
Severity is critical with CVSS v3 score 9.8. No EPSS data available, but the high severity indicates a high likelihood of exploitation in environments where the device is exposed to untrusted networks.
Affected products
- Johnson Controls EasyIO FS32
Scores
- Severity
- critical
- CVSS v2
- 10
- CVSS v3
- 9.8
- CVSS v4
- 8.4
- EPSS
- —