{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/easyio-fg-firmware-2.0b52/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:johnson_controls:easyio_fg_firmware:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-27872"},{"id":"CVE-2026-27873"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["EasyIO FG firmware (\u003c=2.0b52)"],"_cs_severities":["high"],"_cs_tags":["iot","ot","vulnerability","ics"],"_cs_type":"advisory","_cs_vendors":["Johnson Controls"],"content_html":"\u003cp\u003eJohnson Controls EasyIO FG series devices running firmware version 2.0b52 or earlier are susceptible to vulnerabilities identified as CVE-2026-27872 and CVE-2026-27873. These vulnerabilities stem from the use of hard-coded credentials (CWE-798) and improper privilege management (CWE-269), which can be leveraged by an attacker to gain unauthorized access and potentially achieve full device compromise. These devices are used globally in critical infrastructure sectors, including energy, manufacturing, and transportation. Because the EasyIO FG series has reached End-of-Life (EOL) and End-of-Support (EOS) status, Johnson Controls will not issue any firmware patches or code-level fixes. Organizations currently utilizing these devices in their OT/BAS networks must rely on strict network segmentation and compensatory controls to mitigate the risk of unauthorized access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows an attacker to bypass authentication mechanisms and elevate privileges, leading to full control over affected EasyIO FG hardware. Given the role of these devices in critical infrastructure such as energy and manufacturing, a compromise could result in operational disruptions, unauthorized manipulation of physical processes, or lateral movement into broader OT environments. Since no patches are available, the risk remains persistent for any device left connected to a network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate all instances of the EasyIO FG series to current, supported hardware, such as the EasyIO Neo R1 Series, as the affected devices are EOL.\u003c/li\u003e\n\u003cli\u003eImplement strict network isolation for any remaining units by placing them in isolated BAS/OT VLANs with no direct Internet connectivity.\u003c/li\u003e\n\u003cli\u003eConfigure firewalls to allow connections only from whitelisted engineering workstation IP addresses and block all remote login access from untrusted segments.\u003c/li\u003e\n\u003cli\u003eDisable all unnecessary services on the devices, specifically Telnet or other insecure legacy management protocols.\u003c/li\u003e\n\u003cli\u003eMonitor logs for repeated failed login attempts or unauthorized attempts to gain root-level access to the management interface.\u003c/li\u003e\n\u003cli\u003eRefer to the manufacturer's advisory JCI-PSA-2026-12 for detailed mitigation and hardening steps.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T17:12:05Z","date_published":"2026-10-06T17:12:05Z","id":"https://feed.craftedsignal.io/briefs/2026-10-johnson-controls-easyio/","summary":"Johnson Controls EasyIO FG firmware versions \u003c=2.0b52 are affected by hard-coded credentials and improper privilege management vulnerabilities (CVE-2026-27872, CVE-2026-27873), potentially allowing full device compromise.","title":"Hard-coded Credentials and Privilege Management Vulnerabilities in Johnson Controls EasyIO FG","url":"https://feed.craftedsignal.io/briefs/2026-10-johnson-controls-easyio/"}],"language":"en","title":"CraftedSignal Threat Feed - EasyIO FG Firmware (\u003c=2.0b52)","version":"https://jsonfeed.org/version/1.1"}