IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Johnson Controls EasyIO FG

HIGH
CVSS 7.7
Date 2026-10-06T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2026-27873 7.7 high
A vulnerability exists in EasyIO FG relating to an attacker gaining unauthorized access to the system through hard-coded credentials and improper privilege management, potentially resulting in full device compromise. Successful exploitation could result in technical or operational impact.
CVE-2026-27872 7.7 high
A vulnerability exists in EasyIO FG relating to an attacker gaining unauthorized access to the system through hard-coded credentials and improper privilege management, potentially resulting in full device compromise. Successful exploitation could result in technical or operational impact.

// Remediations (18)

Mitigation: Enable logging and centralized monitoring (where supported)
Enable logging and centralized monitoring (where supported)
Mitigation: Block all Internet-originated traffic
Block all Internet-originated traffic
Mitigation: Block all remote login access from untrusted networks
Block all remote login access from untrusted networks
Mitigation: Prevent unauthorized lateral movement across networks
Prevent unauthorized lateral movement across networks
Mitigation: Ensure no direct Internet exposure
Ensure no direct Internet exposure
Mitigation: Enforce strict VLAN segmentation from enterprise IT networks
Enforce strict VLAN segmentation from enterprise IT networks
Mitigation: Disable insecure services (e.g., Telnet), if enabled
Disable insecure services (e.g., Telnet), if enabled
Mitigation: Restrict access to trusted engineering workstations only
Restrict access to trusted engineering workstations only
Mitigation: Johnson Controls has determined that the EasyIO FG Series has reached End-of-Life (EOL) and End-of-S
Johnson Controls has determined that the EasyIO FG Series has reached End-of-Life (EOL) and End-of-Support (EOS) status. The product has not been manufactured or sold since prior to 2019, and the source code is no longer available. As a result, no firmware patch or code-level fix will be issued. Users are advised to migrate to supported current-generation products (e.g., EasyIO Neo R1 Series).
Mitigation: Restrict distribution of firmware images
Restrict distribution of firmware images
Mitigation: For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI
For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-12 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
Mitigation: Allow connections only from whitelisted IP addresses
Allow connections only from whitelisted IP addresses
Mitigation: Disable any unnecessary services or exposed ports
Disable any unnecessary services or exposed ports
Mitigation: Prevent unauthorized physical and console access
Prevent unauthorized physical and console access
Mitigation: Monitor for unauthorized or root-level access
Monitor for unauthorized or root-level access
Mitigation: Restrict communication to required protocols only
Restrict communication to required protocols only
Mitigation: Monitor for repeated login attempts
Monitor for repeated login attempts
Mitigation: Deploy devices only within isolated BAS/OT networks
Deploy devices only within isolated BAS/OT networks

// References