View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873) CVSS Vendor Equipment v3 7.7 Johnson Controls EasyIO FG firmware 2 Vulnerabilities Use of Hard-coded Credentials, Improper Privilege…
Read at CISA Cybersecurity Advisories
CVE-2026-27872
- Severity
- 5.6 Medium · CVSS 4.0 · Jci
- Exploited
- Not in CISA’s catalog
- Published
- Johnson Controls Easy IO FG
Affected: before 2.0b52
Fixed: 2.0b52
CVE-2026-27873
- Severity
- 5.6 Medium · CVSS 4.0 · Jci
- Exploited
- Not in CISA’s catalog
- Published
- Johnson Controls EasyIO FG
Affected: before 2.0b52
Fixed: 2.0b52