Insecure Default Initialization Vulnerability in Johnson Controls EasyIO FS32
CVE-2026-71448
5.6MEDIUM
What is CVE-2026-71448?
The EasyIO FS32 product by Johnson Controls is affected by a vulnerability that allows authentication abuse due to insecure default initialization of resources. This issue compromises the integrity of the system and permits unauthorized access, potentially enabling attackers to exploit the device functionalities. Users are advised to update to version 3.0b63 or later to mitigate this risk.
Affected Version(s)
EasyIO FS32 0 < 3.0b63
References
CVSS V4
Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gabriele Gardois, Zachary Bushell and Lorenzo De Carli
