Johnson Controls TL280 Devices Vulnerable to Hardcoded Credentials and Weak Cryptography
CISA has issued an advisory for Johnson Controls Inc. TL280 devices, warning of vulnerabilities related to hardcoded credentials and broken cryptographic algorithms.

CISA has released an advisory detailing critical security flaws affecting Johnson Controls Inc. TL280 devices, specifically those running firmware versions prior to 5.63. The vulnerabilities, identified under CVE-2026-27871, stem from the use of hardcoded credentials and a broken cryptographic algorithm within the device's firmware.
Hardcoded credentials, which are embedded directly into the source code, present a significant security risk by providing attackers with static authentication information. When combined with a broken or risky cryptographic algorithm, these credentials can be more easily compromised or bypassed, potentially allowing unauthorized access to sensitive data stored on the device. The CVSS v3.1 score for this vulnerability is rated as MEDIUM (4.1), with a high attack complexity, indicating that while exploitation is not trivial, the potential impact is notable.
The affected product, Johnson Controls Inc. TL280, is deployed globally across various critical infrastructure sectors, including Critical Manufacturing, Commercial Facilities, Government Services and Facilities, and Transportation Systems. This widespread deployment increases the potential impact should an attacker successfully exploit the vulnerability.
Successful exploitation of CVE-2026-27871 could allow an attacker to gain access to sensitive information residing on the TL280 device. While no public exploitation has been reported to CISA at this time, the nature of the vulnerability necessitates proactive security measures.
Johnson Controls recommends applying firmware update version 5.63 as the primary remediation to address these vulnerabilities. In addition to the firmware update, the company suggests several defensive measures to mitigate risks. These include restricting network access to affected devices, monitoring access logs for anomalous activity, and rotating any credentials that might be derived from or associated with the hard-coded values.
Further mitigation strategies recommended by Johnson Controls and CISA involve robust network segmentation, placing ICS/SCADA devices behind firewalls, and ensuring these devices are not directly exposed to the internet or untrusted network segments. When remote access is necessary, secure methods such as Virtual Private Networks (VPNs) should be employed, with the understanding that VPNs themselves must be kept up-to-date.
CISA also emphasizes the importance of minimizing network exposure for all control system devices and performing regular firmware integrity checks. Organizations are encouraged to implement defense-in-depth strategies and conduct thorough impact and risk assessments before deploying any defensive measures. Detailed mitigation instructions can be found in Johnson Controls Product Security Advisory JCI-PSA-2026-08.
The advisory highlights the ongoing challenges in securing industrial control systems, where vulnerabilities like hardcoded credentials and weak cryptography can have far-reaching consequences due to the critical nature of the systems they protect.