Cryptographic Algorithm Flaw in Johnson Controls TL280
CVE-2026-27871

2.9LOW

Key Information:

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-27871?

The TL280 product from Johnson Controls suffers from a vulnerability related to the use of a broken or risky cryptographic algorithm. This flaw potentially allows attackers to perform cryptanalytic attacks, compromising the integrity and confidentiality of sensitive data. Affected versions are prior to 5.63. Users are encouraged to update to the latest version to mitigate associated risks. For more information on security advisories, visit the Johnson Controls Trust Center.

Affected Version(s)

TL280 0 < 5.63

References

CVSS V4

Score:
2.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zach Hackett
.