Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Johnson Controls — Vulnerabilities & Security Advisories 101

Browse all 101 CVE security advisories affecting Johnson Controls. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Johnson Controls operates as a global leader in building technologies, providing integrated solutions for heating, ventilation, air conditioning, and security systems. With 76 recorded Common Vulnerabilities and Exposures (CVEs), the company’s software ecosystem has historically been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from legacy components within its building management platforms, exposing critical infrastructure to potential unauthorized access or data exfiltration. While no single catastrophic public breach has defined its recent history, the sheer volume of disclosed CVEs highlights systemic challenges in securing interconnected industrial control systems. Security researchers frequently identify these weaknesses as entry points for lateral movement within enterprise networks. Consequently, maintaining rigorous patch management and network segmentation remains essential for mitigating risks associated with Johnson Controls’ extensive hardware and software footprint in commercial and industrial environments.

CVE ID Title CVSS Severity Published
CVE-2026-27873 Johnson Controls EasyIO FG <2.0b52 硬编码凭据漏洞 — EasyIO FG CWE-798 5.6 Medium 2026-10-01
CVE-2026-64893 Johnson Controls EasyIO NEO <3.3b25 明文传输漏洞 — EasyIO NEO CWE-319 7.3 High 2026-10-01
CVE-2026-64892 Johnson Controls Easy IO Neo 3.3b63前敏感信息泄露 — Easy IO Neo CWE-200 6.3 Medium 2026-10-01
CVE-2026-34494 Johnson Controls Neo Series MVP2 (<3.3b63) On-Chip调试接口数据收集漏洞 — Neo Series MVP2 CWE-1191 7.2 High 2026-10-01
CVE-2026-34493 Johnson Controls EasyIO FS32 <3.3b63 芯片调试接口漏洞 — EasyIO FS32 CWE-1191 7.2 High 2026-10-01
CVE-2026-71449 Johnson Controls EasyIO FS32 硬编码密钥漏洞 — EasyIO FS32 CWE-321 9.3 Critical 2026-10-01
CVE-2026-71448 EasyIO FS32 <3.0b63 不安全资源初始化认证滥用漏洞 — EasyIO FS32 CWE-1188 5.6 Medium 2026-10-01
CVE-2026-71453 Johnson Controls EasyIO FS32 (<3.0b63) 路径遍历漏洞 — EasyIO FS32 CWE-73 5.6 Medium 2026-10-01
CVE-2026-71452 Johnson Controls EasyIO FS32 3.0b63以下命令注入漏洞 — EasyIO FS32 CWE-78 7.2 High 2026-10-01
CVE-2026-71451 Johnson Controls EasyIO FS32 < 3.0b63 命令注入漏洞 — EasyIO FS32 CWE-78 5.6 Medium 2026-10-01
CVE-2026-27874 EasyIO FS32硬编码凭据漏洞 — EasyIO FS32 CWE-798 5.0 Medium 2026-10-01
CVE-2026-27872 EasyIO FG — Easy IO FG CWE-269 5.6 Medium 2026-10-01
CVE-2026-64896 T2000 open debug port — T2000 5.2 Medium 2026-08-27
CVE-2026-34491 Johnson Controls Metasys 14 安全漏洞 — Metasys 14 6.1 Medium 2026-08-24
CVE-2026-27875 Simplex Incident Manager Clear Test — Simplex Incident Manager / Autocall Fire Administrator CWE-316 6.9 Medium 2026-08-21
CVE-2026-34492 Airwall - Arbitrary file read — Airwall CWE-73 7.0 High 2026-08-14
CVE-2026-64887 Airwall - Hardcoded Secrets — Airwall CWE-321 7.0 High 2026-08-14
CVE-2026-27871 TL280 — TL280 2.9 Low 2026-08-14
CVE-2026-34497 FMS Employee Vulnerable to HTML Injection — FM Systems Employee CWE-80 4.8 Medium 2026-07-31
CVE-2026-34495 FMS Employee vulnerable to XSS — FM Systems Employee CWE-79 4.8 Medium 2026-07-31
CVE-2026-21662 FMS Employee Allows Upload of Unrestricted Files — FM Systems Employee CWE-434 4.8 Medium 2026-07-31
CVE-2026-34490 XAAP Android Data Stored in Unencrypted Database — XAAP Application CWE-312 4.8 Medium 2026-07-31
CVE-2026-34496 victor Web - Priviledge Escalation — victor Web 7.1 High 2026-07-23
CVE-2026-21653 CCure and Victor Application Server - Server Side Request Forgery — CCure 9000 and victor application server 7.2 High 2026-07-23
CVE-2026-21661 AC2000 Uncontrolled Search Path Element — AC2000 CWE-427 8.4 High 2026-05-06
CVE-2026-21660 Johnson Controls-Frick Quantum HD-Hardcoded Email Credentials Saved as Plaintext in Firmware — Frick Controls Quantum HD CWE-256 6.9 Medium 2026-02-27
CVE-2026-21659 Johnson Controls -Frick Quantum HD-Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion — Frick Controls Quantum HD CWE-23 9.8 - 2026-02-27
CVE-2026-21658 Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution — Frick Controls Quantum HD CWE-94 9.8 - 2026-02-27
CVE-2026-21657 Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution — Frick Controls Quantum HD CWE-94 6.8 - 2026-02-27
CVE-2026-21656 Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution — Frick Controls Quantum HD CWE-94 6.8 - 2026-02-27

This page lists every published CVE security advisory associated with Johnson Controls. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.