Johnson Controls EasyIO FG
CISA says end-of-life Johnson Controls EasyIO FG firmware has hard-coded credential flaws and will not be patched.
CISA published an advisory for Johnson Controls EasyIO FG firmware 2.0b52 and earlier. CVE-2026-27872 and CVE-2026-27873 involve hard-coded credentials and improper privilege management that could give an attacker full device access; both are scored CVSS 7.7 and require local access with high complexity. The series is end-of-life and end-of-support, unsold since before 2019, and no firmware fix will be issued. Operators are told to migrate to EasyIO Neo and keep devices off the internet on segmented building-automation networks. Exploitation is not reported.