Critical Vulnerabilities Discovered in Johnson Controls EasyIO FG Firmware; Product Reaches End-of-Life
CISA and Johnson Controls have disclosed two vulnerabilities, CVE-2026-27872 and CVE-2026-27873, affecting EasyIO FG firmware versions 2.0b52 and below. The flaws stem from the use of hard-coded credentials and improper privilege management, which could allow an attacker to gain full unauthorized access to the device. Johnson Controls has confirmed that the EasyIO FG Series has reached End-of-Life (EOL) and End-of-Support (EOS) status; the product has not been manufactured or sold since prior to 2019, and the source code is no longer available, meaning no firmware patch will be issued. Users are strongly advised to migrate to supported current-generation products such as the EasyIO Neo R1 Series. In the absence of a patch, the vendor and CISA recommend deploying devices within isolated Building Automation System (BAS) / Operational Technology (OT) networks, ensuring no direct Internet exposure, enforcing strict VLAN segmentation, restricting remote login access, and implementing IP whitelisting and traffic blocking measures.
















