OS Command Injection Found in Johnson Controls EasyIO FS32 Product
CVE-2026-71452
7.2HIGH
What is CVE-2026-71452?
An OS Command Injection vulnerability in Johnson Controls' EasyIO FS32 product allows attackers to execute arbitrary commands on the underlying operating system. This vulnerability can be exploited by sending specially crafted input, enabling unauthorized access and control over system operations. The affected versions are those released prior to 3.0b63. Users are advised to apply available patches and review security measures to mitigate exposure.
Affected Version(s)
EasyIO FS32 0 < 3.0b63
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gabriele Gardois, Zachary Bushell and Lorenzo De Carli
