OS Command Injection Found in Johnson Controls EasyIO FS32 Product
CVE-2026-71452

7.2HIGH

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-71452?

An OS Command Injection vulnerability in Johnson Controls' EasyIO FS32 product allows attackers to execute arbitrary commands on the underlying operating system. This vulnerability can be exploited by sending specially crafted input, enabling unauthorized access and control over system operations. The affected versions are those released prior to 3.0b63. Users are advised to apply available patches and review security measures to mitigate exposure.

Affected Version(s)

EasyIO FS32 0 < 3.0b63

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Gardois, Zachary Bushell and Lorenzo De Carli
.