External Control of File Name Vulnerability in Johnson Controls EasyIO FS32
CVE-2026-71453

5.6MEDIUM

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-71453?

The EasyIO FS32 by Johnson Controls exhibits a vulnerability where external inputs can influence file names or paths, allowing potential attackers to conduct path traversal attacks. This could enable unauthorized access to sensitive files or directories, compromising the integrity and confidentiality of the system. Users of EasyIO FS32 are advised to update to version 3.0b63 or later to mitigate this risk effectively.

Affected Version(s)

EasyIO FS32 0 < 3.0b63

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Gardois, Zachary Bushell and Lorenzo De Carli
.