Hard-coded Credentials Vulnerability in Johnson Controls EasyIO FG
CVE-2026-27873

5.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-27873?

The EasyIO FG by Johnson Controls is susceptible to a Use of Hard-coded Credentials vulnerability. This flaw facilitates password spraying attacks, allowing unauthorized access to the system. Users operating versions before 2.0b52 are especially at risk. It's crucial for users to apply security best practices and update to secure versions to mitigate the risk associated with this vulnerability.

Affected Version(s)

EasyIO FG 0 < 2.0b52

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Gardois, Zachary Bushell and Lorenzo De Carli
.