rootpwn

critical · CVSS v3 9.8 · CVSS v4 7.2

CVE-2026-71453

Johnson Controls EasyIO FS32 devices before 3.0b63 are vulnerable to external control of file name or path, enabling directory traversal. At

Overview

Johnson Controls EasyIO FS32 devices before 3.0b63 are vulnerable to external control of file name or path, enabling directory traversal. Attackers can read or write arbitrary files on the device filesystem, potentially exposing sensitive data or disrupting operation.

Description

- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.

Impact

The flaw compromises confidentiality, integrity, and availability of data stored on the device. Attackers could exfiltrate configuration files, tamper with firmware, or cause denial of service. Defenders must assess the risk to industrial control systems and critical infrastructure that rely on EasyIO FS32.

Remediation

Apply the vendor‑supplied firmware update to version 3.0b63 or later. If an update is not immediately available, restrict network access to the device, disable remote file upload interfaces, and enforce strict file path validation on any custom scripts interacting with the device.

Risk context

Severity is critical with a CVSS v3 score of 9.8, indicating a high likelihood of exploitation. The absence of EPSS data suggests no recent exploitation reports, but the critical rating warrants prompt action.

Affected products

  • Johnson Controls EasyIO FS32

Scores

Severity
critical
CVSS v2
6.4
CVSS v3
9.8
CVSS v4
7.2
EPSS
—

directory-traversal file-inclusion industrial-control firmware critical Johnson-Controls EasyIO

← All CVEs