Johnson Controls EasyIO Neo Series Controllers Vulnerable to Cleartext Data Transmission
CVE-2026-64893 affects EC and CW controller firmware; attackers may intercept credentials and session data
Key Takeaways
- CVE-2026-64893 affects EasyIO Neo Series EC and CW Controllers on firmware versions V3.3b62, V3.3b63, V3.3b24, and V3.3b25.
- The vulnerability involves cleartext transmission of sensitive information, potentially allowing interception of credentials and session data.
- Fixed firmware versions are available: EC V3.3b64 and CW V3.3b26.
- No public exploit has been confirmed, but risk remains due to unencrypted HTTP traffic.
- Mitigation includes enforcing HTTPS/TLS, disabling HTTP, network segmentation, and VPN use for remote access.
Related Security News
CISA Advises of Sensitive Information Exposure in Johnson Controls EasyIO Neo Series Controllers
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory regarding CVE-2026-64892, a vulnerability in Johnson Controls EasyIO Neo Series EC and CW Controllers that could allow an attacker to gain access to sensitive information. The flaw stems from improper access controls in building automation controllers and impacts four specific firmware versions. Johnson Controls has released fixed firmware versions V3.3b64 (EC) and V3.3b26 (CW) to address the issue.
