Insecure Default Initialization Vulnerability in Johnson Controls EasyIO FS32
CVE-2026-71448

5.6MEDIUM

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-71448?

The EasyIO FS32 product by Johnson Controls is affected by a vulnerability that allows authentication abuse due to insecure default initialization of resources. This issue compromises the integrity of the system and permits unauthorized access, potentially enabling attackers to exploit the device functionalities. Users are advised to update to version 3.0b63 or later to mitigate this risk.

Affected Version(s)

EasyIO FS32 0 < 3.0b63

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Gardois, Zachary Bushell and Lorenzo De Carli
.