Security/ ics-security · johnson-controls · critical-infrastructure · cisa

Johnson Controls EasyIO FG Flaws Will Never Be Patched

Two hard-coded-credential bugs let attackers fully take over EOL building-automation controllers, and Johnson Controls says no fix is coming.

CISA says two security holes in a discontinued Johnson Controls building controller have no fix coming - and never will.

The advisory, published October 6, 2026, covers EasyIO FG building-automation controllers running firmware 2.0b52 or earlier. Two flaws, CVE-2026-27872 and CVE-2026-27873, both trace back to hard-coded credentials paired with improper privilege management, each scoring 7.7 on CVSS 3.1. An attacker who reaches the device locally can use those baked-in logins to seize full control. Johnson Controls confirms EasyIO FG left production before 2019 and the source code no longer exists, so there is no patch, period - the fix is to buy the newer EasyIO Neo R1 and swap the old unit out. University of Calgary researchers Gabriele Gardois, Zachary Bushell, and Lorenzo De Carli reported the bugs.

Building-automation controllers like this one run HVAC, lighting, and access systems inside factories, government buildings, transit hubs, and energy facilities worldwide - not hobby gear. CISA's mitigation list is really a checklist for how the device should have been deployed all along: no internet exposure, strict network segmentation, no remote logins from untrusted networks. That the primary fix for a hard-coded password is stop making the password reachable says plenty about how little room this generation of industrial hardware left for recovering from its own design mistakes.

Seven years out of production and still wired into critical infrastructure - this is less a software bug than a procurement problem.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →