Johnsoncontrols Vulnerabilities
Comprehensive security vulnerability database for Johnsoncontrols products
6
0
5
0
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2026-21660 | 6.9 | This vulnerability allows an attacker to gain unauthorized access to the Frick Controls Quantum HD system by using hardcoded email credentials that are stored in plain text, making them easy to find. It affects versions 10.22 and earlier, meaning any system running these versions is at risk if the attacker can access the firmware. | johnsoncontrolsfrick controls quantum hd firmware | Theoretical | about 1 month agoFeb 27, 2026 |
| CVE-2026-21659 | 8.7 | This vulnerability allows an attacker to remotely run any code on the affected Frick Controls Quantum HD devices without needing to log in, which can completely take over the system. It affects versions 10.22 and earlier, meaning any device running these versions is at risk if exposed to the internet. | johnsoncontrolsfrick controls quantum hd firmware | Exploit Available | about 1 month agoFeb 27, 2026 |
| CVE-2026-21658 | 8.8 | An attacker can remotely execute malicious code on Johnson Controls Frick Controls Quantum HD devices without needing to log in, due to poor input validation in certain settings. This vulnerability affects versions 10.22 and earlier, allowing unauthorized actions that could compromise the device's security. | johnsoncontrolsfrick controls quantum hd firmware | Exploit Available | about 1 month agoFeb 27, 2026 |
| CVE-2026-21657 | 8.8 | An attacker can inject malicious code into the Frick Controls Quantum HD device, potentially allowing them to execute unauthorized actions before the device requires any login. This vulnerability affects versions 10.22 and earlier, and it arises from the device not properly checking the input it receives. | johnsoncontrolsfrick controls quantum hd firmware | Exploit Available | about 1 month agoFeb 27, 2026 |
| CVE-2026-21656 | 8.8 | This vulnerability allows an attacker to inject malicious code into the Frick Controls Quantum HD device, potentially taking control of it before any user authentication is required. It affects versions 10.22 and earlier, and it arises from the device not properly checking the input it receives. | johnsoncontrolsfrick controls quantum hd firmware | Exploit Available | about 1 month agoFeb 27, 2026 |
| CVE-2026-21654 | 8.8 | An attacker can exploit a flaw in Johnson Controls Frick Controls Quantum HD to run unauthorized commands on the device before any user authentication takes place. This vulnerability affects versions 10.22 and earlier, and it arises from the device not properly checking certain inputs, which could lead to unexpected and potentially harmful actions. | johnsoncontrolsfrick controls quantum hd firmware | Exploit Available | about 1 month agoFeb 27, 2026 |
About Johnsoncontrols Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Johnsoncontrols products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.