Use of Hard-coded Credentials Vulnerability in Johnson Controls EasyIO FS32
CVE-2026-27874

5.9MEDIUM

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-27874?

The EasyIO FS32 by Johnson Controls is vulnerable due to the use of hard-coded credentials, allowing potential exploitation through default or predetermined login details. This issue impacts versions prior to 3.0b63, posing significant security risks for devices that have not been updated. Users are advised to review their device configurations and implement necessary updates to mitigate the threat.

Affected Version(s)

EasyIO FS32 0 < 3.0b63

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Gardois
.