rootpwn

critical · CVSS v3 9.8 · CVSS v4 8.4

CVE-2026-71452

Johnson Controls EasyIO FS32 devices prior to version 3.0b63 are vulnerable to OS command injection, allowing attackers to execute arbitrary

Overview

Johnson Controls EasyIO FS32 devices prior to version 3.0b63 are vulnerable to OS command injection, allowing attackers to execute arbitrary shell commands. The flaw can be triggered via network interfaces exposed by the device. This vulnerability could compromise building automation systems and critical infrastructure.

Description

- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.

Impact

Confidentiality: attackers can read sensitive configuration and logs. Integrity: attackers can modify device settings or firmware. Availability: attackers can crash or lock out the device, disrupting building operations. Impacted parties include facility managers, network administrators, and building automation operators.

Remediation

Apply the latest firmware update (3.0b63 or newer) from Johnson Controls. If immediate update is not possible, restrict network access to the device using firewall rules or VLAN segmentation, and disable unused management interfaces. Monitor logs for suspicious command execution attempts.

Risk context

Severity is critical with CVSS v3 score 9.8. No EPSS data available, but the high severity indicates a high likelihood of exploitation in environments where the device is exposed to untrusted networks.

Affected products

  • Johnson Controls EasyIO FS32

Scores

Severity
critical
CVSS v2
10
CVSS v3
9.8
CVSS v4
8.4
EPSS
—

OS Command Injection Johnson Controls EasyIO FS32 Critical Building Automation Command Injection Firmware Update

← All CVEs