OS Command Injection in Johnson Controls EasyIO FS32
CVE-2026-71451

7.2HIGH

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-71451?

An OS Command Injection vulnerability exists in the Johnson Controls EasyIO FS32 that allows an attacker to execute arbitrary commands on the affected system. This vulnerability is present in versions prior to 3.0b63 and could lead to unauthorized access and manipulation of sensitive data, posing significant security risks.

Affected Version(s)

EasyIO FS32 0 < 3.0b63

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Gardois
.