Description
- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.

This issue affects EasyIO FG: before 2.0b52.
Published: 2026-10-01
Score: 5.6 Medium
EPSS: n/a
KEV: No
Impact: Authentication Bypass via Hard‑coded Credentials
Action: Patch Update
AI Analysis

Impact

An attacker can take advantage of hard‑coded credentials in Johnson Controls EasyIO FG. The use of fixed passwords permits password‑spraying attacks, enabling an adversary to guess or iterate passwords until successful authentication. Successful exploitation can lead to unauthorized control over the device, compromise of configuration data, and potential lateral movement within the associated environment. The weakness is classified as CWE-798, Hard‑coded Credentials.

Affected Systems

Johnson Controls EasyIO FG firmware versions older than 2.0b52 are affected. The vulnerability is present only in releases before 2.0b52, and no later firmware versions are known to contain the issue.

Risk and Exploitability

The CVSS score of 5.6 indicates moderate severity. The EPSS score is not available, and the vulnerability has not been listed in the CISA KEV catalog. Attackers are likely to target the device over the network since hard‑coded credentials are accessible via management interfaces, though the exact vector is not explicitly specified in the advisory. Given the moderate score and lack of publicly known exploits, the overall risk is moderate but should be addressed promptly.

Generated by OpenCVE AI on October 1, 2026 at 22:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade EasyIO FG firmware to version 2.0b52 or later to remove hard‑coded credentials
  • If an upgrade is not immediately possible, change the default credentials to strong, unique passwords
  • Restrict network access to the EasyIO FG management interface using firewall rules or VPN so only authorized hosts can connect

Generated by OpenCVE AI on October 1, 2026 at 22:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Title Hard‑coded Credentials Allow Password Spraying in Johnson Controls EasyIO FG
First Time appeared Johnson Controls easy Io Fg
Vendors & Products Johnson Controls easy Io Fg

Thu, 01 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description - Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.
First Time appeared Johnson Controls
Johnson Controls easyio Fg
Weaknesses CWE-798
CPEs cpe:2.3:a:johnson_controls:easyio_fg:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls easyio Fg
References
Metrics cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Johnson Controls Easy Io Fg Easyio Fg
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-10-01T21:42:09.453Z

Reserved: 2026-02-24T11:29:18.530Z

Link: CVE-2026-27873

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:01.450

Modified: 2026-10-01T22:17:01.450

Link: CVE-2026-27873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:30:14Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials