CVE-2026-27873
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are a...
Affects 0 products across 1 vendor.
Software contains embedded passwords or keys that cannot be changed by the administrator.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A unscored severity vulnerability (CVE-2026-27873) affects the target system. - Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-27873?
Is CVE-2026-27873 actively exploited?
How do I remediate CVE-2026-27873?
What systems are affected by CVE-2026-27873?
| CVE ID | CVE-2026-27873 |
|---|---|
| Published | 2026-10-01 |
| Last Modified | 2026-10-06 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Source | NVD |
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873) CVSS Vendor Equipment v3 7.7 Johnson Controls EasyIO FG firmware 2 Vulnerabilities Use of Hard-coded Credentials, Improper Privilege Management Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities
Source: NIST NVD / MITRE CVE Database
| Vendor | Product | Affected Versions |
|---|---|---|
| Johnsoncontrols | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA known-exploited | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.
Create a free account →