VYPR
advisoryPublished Oct 6, 2026· 1 source

CISA Warns of Hard-Coded Credentials in End-of-Life Johnson Controls EasyIO FG Firmware

CISA has identified two critical vulnerabilities in Johnson Controls EasyIO FG firmware versions <=2.0b52, stemming from hard-coded credentials and improper privilege management.

CISA has issued an advisory detailing two critical vulnerabilities, CVE-2026-27872 and CVE-2026-27873, affecting Johnson Controls EasyIO FG firmware versions up to and including 2.0b52. These vulnerabilities are rooted in the use of hard-coded credentials and improper privilege management within the firmware, which could allow a remote attacker to gain full unauthorized access to the affected devices.

The affected product, Johnson Controls EasyIO FG firmware, has reached its End-of-Life (EOL) and End-of-Support (EOS) status. It has not been manufactured or sold since prior to 2019, and the source code is no longer available. Consequently, Johnson Controls will not be issuing any firmware patches or code-level fixes for these vulnerabilities. Users are strongly advised to migrate to currently supported product lines, such as the EasyIO Neo R1 Series.

Exploitation of these flaws could lead to significant technical or operational impacts within critical infrastructure environments. The vulnerabilities are particularly concerning given the widespread deployment of such systems in sectors including Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, and Energy, across the globe.

While no direct patches are available, CISA and Johnson Controls have outlined a series of mitigation strategies. These include deploying devices exclusively within isolated Building Automation System (BAS) or Operational Technology (OT) networks, ensuring no direct internet exposure, and enforcing strict VLAN segmentation from enterprise IT networks. Access should be restricted to trusted engineering workstations only, with all remote login access from untrusted networks blocked.

Further recommended mitigations involve allowing connections only from whitelisted IP addresses, blocking all internet-originated traffic, and preventing unauthorized lateral movement across networks. Organizations should also restrict communication to required protocols only, disable insecure services like Telnet if enabled, and turn off any unnecessary services or exposed ports. Monitoring for repeated login attempts and unauthorized or root-level access is also crucial.

Johnson Controls also recommends enabling logging and centralized monitoring where supported, restricting the distribution of firmware images, and preventing unauthorized physical and console access. For more detailed guidance, users are directed to Johnson Controls Product Security Advisory JCI-PSA-2026-12.

The vulnerabilities have been assigned CVSS v3.1 base scores of 7.7 (HIGH) and CVSS v4.0 scores of 7.2 (HIGH), reflecting the severity of potential impacts. The Common Weakness Enumeration (CWE) identified is CWE-798: Use of Hard-coded Credentials. The advisory underscores the risks associated with using end-of-life industrial control system components and the importance of proactive migration and robust network segmentation.

This advisory serves as a critical reminder for organizations managing industrial control systems to regularly assess their hardware and software for end-of-life status and associated security risks. The lack of available patches for these legacy devices necessitates a strategic approach to replacement and enhanced security measures to protect against potential exploitation.

Synthesized by Vypr AI