Critical Vulnerabilities Discovered in Johnson Controls EasyIO FG Firmware; Product Reaches End-of-Life
Two CVEs involve hard-coded credentials and privilege management flaws; no patch available as vendor declares EOL/EOS
Key Takeaways
- Two critical vulnerabilities (CVE-2026-27872, CVE-2026-27873) affect EasyIO FG firmware <=2.0b52, involving hard-coded credentials and improper privilege management.
- Johnson Controls has declared the EasyIO FG Series End-of-Life/End-of-Support; no firmware patch will be issued.
- The product has not been manufactured or sold since prior to 2019; source code is unavailable.
- Users are advised to migrate to supported current-generation products such as the EasyIO Neo R1 Series.
Related Security News

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet with STUN-Based C2
Nozomi Networks researchers report that threat actors have been attempting to exploit a critical vulnerability in the Realtek Jungle SDK. The exploitation delivers Cling botnet malware, which is notable for repurposing ordinary STUN (Session Traversal Utilities for NAT) behavior into a practical command-and-control channel. The vulnerability has since been patched. Users of the Realtek Jungle SDK are advised to update to the latest version to mitigate exploitation risk.



