Executive Summary

CVE-2026-64892 is an information disclosure flaw in Johnson Controls EasyIO Neo Series EC and CW controllers that lets an attacker obtain sensitive information suitable for staging further attacks against the controller and the network it serves. These are field-level building automation controllers governing HVAC, lighting, and mechanical plant, so the practical risk is a loss of confidentiality that erodes the boundary protecting physical building systems.

Technical Exposure Breakdown

The grounding data identifies the vulnerable component as the EasyIO Neo Series EC Controllers at V3.3b63 and V3.3b62, and the EasyIO Neo Series CW Controllers at V3.3b25. No CVSS score and no confirmed patch status are available at the time of writing, so treat remediation timing as unknown and plan for an extended exposure window.

The disclosed detail is limited to the class of weakness: successful exploitation yields access to sensitive information. In building automation controllers this category typically covers configuration data, credential material, network topology, device identifiers, or session artifacts that can be read without full compromise of the device. Any of those items reduces the work factor for a subsequent attack. An attacker who harvests valid credentials or internal addressing from one controller can pivot to adjacent devices on the same field bus or supervisory network.

The attack vector and preconditions are not specified in the source, so do not assume this is purely remote or purely local. Treat it as reachable by any party with network line of sight to the controller management interface until the vendor advisory states otherwise. EasyIO Neo controllers are commonly deployed with web and BACnet IP interfaces exposed on flat building networks, which is the condition that turns an information leak into a usable reconnaissance primitive.

OT Impact and Compliance Risk

Information disclosure does not directly actuate a physical process, but it degrades the segmentation and authentication assumptions that OT environments rely on. For a building automation deployment, the downstream consequence is an attacker who understands your control logic, device inventory, and credential scheme well enough to manipulate setpoints, override schedules, or disable mechanical safeties in a later stage.

Under IEC 62443, this maps to failures in system integrity and confidentiality requirements at the component and zone level. For critical facilities, leaked credentials or topology data undermine the access control and network boundary controls that NERC CIP expects for cyber assets and the segmentation posture TSA SD-02C requires for pipeline operators. Water and wastewater utilities subject to AWIA 2018 risk assessment obligations should log this as a confidentiality exposure in any facility where EasyIO controllers manage plant HVAC or building systems adjacent to process networks.

Compensating Controls

Do not run active vulnerability scans against these controllers to confirm exposure. Field-level building automation hardware is frequently fragile under aggressive probing, and active scanning can hang or brick the device. Build your inventory from passive traffic monitoring and from configuration records instead.

Because patch status is unknown, confirm availability directly with Johnson Controls and stage any firmware update through a maintenance window with a tested rollback, not an opportunistic in-band push.

BreachSpider Intel

BreachSpider tracks CVE-2026-64892 and the broader EasyIO Neo advisory lifecycle so OT teams can monitor affected version coverage, patch availability, and known exploited vulnerability catalog status as they change.